hubspot-deal-pipeline-automation
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
SecuritySecurityreferences/implementation-guide.md
MEDIUMSecurityMEDIUM
references/implementation-guide.md
The visible code appears intended for legitimate HubSpot quota polling and schema validation, with no clear malware or obfuscated payload. The principal security concern is an apparently unauthenticated CRM data proxy that accepts arbitrary identifiers and uses a privileged HubSpot token, potentially enabling unauthorized data access or upstream API abuse. Input validation, authorization, bounded caching, and review of the omitted shared function and CI script are required.
Confidence: 94%Severity: 72%
Audit Metadata