intercom-enterprise-rbac

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/examples.md

No malicious behavior or supply-chain attack indicators are present in the supplied examples. The code documents legitimate RBAC, OAuth installation, and audit workflows. The OAuth example has a significant security gap because state verification is described but omitted from the shown callback, and workspace_id is trusted directly from a query parameter. These should be validated and bound to the authenticated installation context before persisting the token.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fintercom-enterprise-rbac%2F@867ba3f4b394a4c7fd4f37ec67ba5bc89d033ba1dab3e6cd23c92a45ae9dcd68
Security Audit — socket — intercom-enterprise-rbac