spring-boot-rest-api-standards

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/security-headers.md

The fragment contains no evident malware, backdoor, credential theft, command execution, or suspicious outbound communication. It does contain security risks: an unsafe wildcard credentialed development CORS policy, ambiguous duplicate CORS registration, weakened CSP examples, and an unbounded in-memory rate-limit map. The direct User request binding and unseen WebSocket token validation also require review. These are application security and configuration concerns rather than evidence of malicious package behavior.

Confidence: 91%Severity: 59%
AnomalyLOW
references/examples.md

No clear malicious behavior or supply-chain backdoor is present. The code is ordinary application/tutorial functionality. Security review is warranted because downloadFile does not explicitly enforce filesystem containment, uploaded filenames can control storage names and overwrite existing files, and the WebSocket endpoint permits all origins with no visible authentication or authorization. These issues could enable unauthorized file reads, file replacement, or message abuse depending on deployment configuration.

Confidence: 93%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:09 AM
Package URL
pkg:socket/skills-sh/giuseppe-trisciuoglio%2Fdeveloper-kit%2Fspring-boot-rest-api-standards%2F@f82183fbdd670bf05a2d1049cf01200790e0fa199d53674cee3b86fc308da1af
Security Audit — socket — spring-boot-rest-api-standards