woostack-respond

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/tests/fixtures/sensitive-input.json

No malicious runtime behavior or supply-chain compromise can be concluded from this fragment because it contains no executable code. However, the artifact embeds numerous high-sensitivity secrets (auth tokens, Basic auth material, session cookie, API key, password, database credentials) and even payment card data including CVV. This strongly suggests improper logging/redaction practices that create a major information-disclosure risk in telemetry/log pipelines.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Aug 3, 2026, 03:52 PM
Package URL
pkg:socket/skills-sh/howarewoo%2Fwoostack%2Fwoostack-respond%2F@8291fab45d28244e48b1cc77970c144bb5678c6842a5cabfdc0e26cf1ca36989
Security Audit — socket — woostack-respond