klingai-reference-architecture

Warn

Audited by Socket on Sep 9, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
references/complete-reference-implementation.md

No clear malware or supply-chain backdoor is present. The main security concern is an SSRF vulnerability caused by sending requests to an unrestricted user-supplied webhook_url. Missing authentication, authorization, rate limiting, input bounds, and request timeouts create additional security and availability risks. Restrict webhook destinations, block loopback/private/link-local ranges after DNS resolution, validate inputs, authenticate status access, and add network timeouts and quotas.

Confidence: 97%Severity: 72%
AnomalyLOW
references/docker-compose-setup.md

No direct malicious behavior is evident in the supplied Compose file. The primary risks are unauthenticated host exposure of Redis, handling of the API key through a normal environment variable, mutable unpinned container images, and reliance on externally supplied Dockerfiles and nginx.conf. Review those external artifacts and restrict Redis to an internal network or configure authentication and firewall controls.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fklingai-reference-architecture%2F@cb87c87e4715e52665b4c16c7fa465ec0bc64fa5524e8a0124e7be2fdfde6a26
Security Audit — socket — klingai-reference-architecture