effect-best-practices

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
references/rpc-cluster-patterns.md

No clear evidence of malware or supply-chain sabotage is present in the shown code. The primary security concern is application-level: the HTTP endpoint executes dynamically selected workflows using an unvalidated Schema.Unknown payload and returns an executionId derived from request data rather than the execution result. If authentication/authorization and workflow allowlisting/schema validation are not enforced elsewhere, this endpoint could be abused to trigger unintended workflow behaviors or amplify the impact of malformed payloads.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 2, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fapex-language-support%2Feffect-best-practices%2F@bbef02cde4b7bd25abe031eb3e69e36d3ce6d109766bcb0e359b65b2e4d490bd
Security Audit — socket — effect-best-practices