backend-auth-patterns

Warn

Audited by Socket on Aug 23, 2026

1 alert found:

Security
SecurityMEDIUM
references/auth-passwordless.md

No clear evidence of intentional supply-chain malware or obfuscation is present. The code performs sensitive authentication operations, but the provided WebAuthn registration verification logic appears incomplete (returns true without shown cryptographic verification tied to the stored challenge/credential semantics), and the OAuth flow persists access/refresh tokens without demonstrated secure handling in this fragment. These issues are likely to create significant account-takeover/authentication-bypass risk if not mitigated by surrounding code, and therefore represent a high security risk despite low malware likelihood.

Confidence: 60%Severity: 72%
Audit Metadata
Analyzed At
Aug 23, 2026, 08:01 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fbackend-auth-patterns%2F@1f2852efa98c78406d20e74076aa08d4a75209611b679b48aa1253da8506c083
Security Audit — socket — backend-auth-patterns