hashing-passwords

Fail

Audited by Socket on Mar 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/never-do-this.md

Not malware — this is an instructional or demonstrative file containing multiple critical secret-handling anti-patterns. If these patterns were used in production they would create high-severity risks: credential theft, compliance violations, and account takeover. Immediate remediation: remove storage of third‑party credentials, stop using base64 as protection, stop returning plaintext passwords, and migrate password handling to a KDF (Argon2/bcrypt/scrypt) with per-user salts and proper secret management.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 21, 2026, 08:05 AM
Package URL
pkg:socket/skills-sh/djankies%2Fclaude-configs%2Fhashing-passwords%2F@66bf2461e87e82686a202bad3cbc2acbd737d84f