best-practices-bespoke-design
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecurityfixtures/invalid-confidential-publication.json
MEDIUMSecurityMEDIUM
fixtures/invalid-confidential-publication.json
No executable malware is present in the supplied JSON. The main issue is a significant information-disclosure and compliance risk: ITAR and sensitive material are marked publishable through URL delivery without demonstrated authentication, while leakage testing has not been performed. This appears consistent with an intentionally failing safety fixture rather than malicious package behavior.
Confidence: 98%Severity: 78%
Audit Metadata