security-best-practice

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
rules/input-validation.md

The fragment demonstrates intentionally vulnerable web-application code alongside remediation examples. It contains significant application security risks if the BAD snippets are executed: query/operator injection, open redirect, Host-header poisoning, SSRF, DOM XSS, and mass assignment. The visible content does not indicate malicious package behavior or supply-chain malware, and it is not intentionally obfuscated. Assessment is limited to the supplied fragment; omitted code could alter the overall context.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 18, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/himself65%2Fauth-spec%2Fsecurity-best-practice%2F@50dd99f8cdd59bf9dba8faff1d25c1ac467a24896b0c3c55bf62164bec41f3e8
Security Audit — socket — security-best-practice