frontend-architect
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
AnomalyAnomalyreferences/internal-tools.md
LOWAnomalyLOW
references/internal-tools.md
No clear malware or intentional malicious behavior is present. The code is readable internal-tool architecture with normal authentication, feature-flag, debugging, and deployment functions. Security concerns include a broken public-route-group check, incomplete proof of JWT and downstream identity handling, possible feature-flag IDOR due to client-controlled email and flag values, lack of visible CSRF and input validation, sensitive debug-log exposure, and mutable third-party GitHub Action usage with privileged deployment secrets. The omitted API handlers and Cloudflare configuration must be reviewed before deployment.
Confidence: 94%Severity: 62%
Audit Metadata