backend-web-real-time

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/webrtc-architecture.md

No explicit malware behaviors (backdoor/persistence/command execution/covert exfiltration to unrelated destinations) are evident in this fragment. The primary security concerns are (1) hardcoded/placeholder TURN credentials and coturn static-auth-secret (credential exposure risk if copied into real artifacts), and (2) lack of shown authentication/authorization for signaling room/targeting plus insufficient visible hardening for data-channel/file-transfer and SFU room forwarding. Overall, this is standard WebRTC architecture but could be high-impact for privacy and abuse if deployed without strong session authentication and peer trust controls.

Confidence: 64%Severity: 66%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fbackend-web-real-time%2F@1a6b61a1e833fc9b3e43c5b5512688ca56f27880265f9e5fe5f8f2f0a4e765c1
Security Audit — socket — backend-web-real-time