devops

Fail

Audited by Socket on Jul 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/browser-rendering.md

No deliberate malware or obfuscation detected. Primary issues are insecure patterns: unvalidated navigation (SSRF risk), unsanitized forwarding of full page HTML to an external AI binding (data leakage), and an unconstrained crawler that re-enqueues links (amplification/loop risk). Recommendations: validate and whitelist target URLs, enforce authentication and authorization for handlers and queue actions, sanitize/redact content before sending to AI services, add domain scoping, deduplication and rate limits to the crawler, instrument limits for Durable Object session lifetime, and secure runtime environment bindings. Treat env.* bindings as secrets and avoid exposing session IDs.

Confidence: 90%
Audit Metadata
Analyzed At
Jul 3, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/hotriluan%2Fai-command-center%2Fdevops%2F@9bb4ef8a87318022a233ff7b42c3c62af13e9e98813796f407281491f3a6ea27
Security Audit — socket — devops