effect-best-practices
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalyreferences/rpc-cluster-patterns.md
LOWAnomalyLOW
references/rpc-cluster-patterns.md
No clear evidence of malware or supply-chain sabotage is present in the shown code. The primary security concern is application-level: the HTTP endpoint executes dynamically selected workflows using an unvalidated Schema.Unknown payload and returns an executionId derived from request data rather than the execution result. If authentication/authorization and workflow allowlisting/schema validation are not enforced elsewhere, this endpoint could be abused to trigger unintended workflow behaviors or amplify the impact of malformed payloads.
Confidence: 62%Severity: 55%
Audit Metadata