server-actions

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/form-handling.md

No evidence of intentional malware or supply-chain sabotage is present. The main security concern is the file upload path construction using an attacker-controlled filename, with additional risks from trusting MIME metadata, missing visible authorization and validation, and unbounded dynamic database writes. The upload implementation should not be used without secure filename generation, path containment checks, content validation, and access controls.

Confidence: 97%Severity: 78%
AnomalyLOW
examples/mutation-patterns.md

No evidence of malware, data exfiltration, credential theft, or obfuscated malicious code is present. The server actions expose destructive and write operations and show no visible authentication or authorization checks, creating a potentially significant access-control risk if not enforced elsewhere. Review action-level authorization and ownership validation before use.

Confidence: 93%Severity: 57%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/davepoon%2Fbuildwithclaude%2Fserver-actions%2F@3734f4b6b0d99f47b4a59b1baf4da94352e94563718bb1c2419ac84ef89d8dda