maintainx-enterprise-rbac

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
references/implementation-guide.md

No evidence of intentional malware, credential harvesting, exfiltration, persistence, command execution, or sabotage appears in this fragment. The implementation does contain a potentially serious access-control flaw: filterByLocationAccess creates a new LocationAccessControl whose empty rule set causes full access, and several authorization cases are explicitly fail-open. Audit logging and API-key handling also require review for initialization, redaction, revocation, rate limiting, and enforcement of scoped permissions. Because surrounding definitions and call sites are not visible, the exact exploitability depends on omitted integration code.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 9, 2026, 03:50 AM
Package URL
pkg:socket/skills-sh/jeremylongshore%2Ftons-of-skills-marketplace%2Fmaintainx-enterprise-rbac%2F@a8612ac10b50c965f9b279eb5b5ceae49235fffd78042b8757c13bfaac3e2c62
Security Audit — socket — maintainx-enterprise-rbac