klaviyo-data-handling

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/implementation.md

The code implements legitimate Klaviyo privacy and consent operations and contains no clear malware or supply-chain backdoor. The primary security issue is an injection risk from interpolating an unescaped email into the DSAR filter. Additional privacy risks arise from incomplete secret redaction, raw or partially redacted identifiers in logs, shallow redaction, and long fixed retention. The irreversible deletion and subscription functions require strong caller authorization and input validation.

Confidence: 97%Severity: 61%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:44 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fklaviyo-data-handling%2F@9513cdfde56de68b8e4006c04f48756235ddd68147acf1b19b63db5a0cfd50f4
Security Audit — socket — klaviyo-data-handling