workflow-devkit
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalytemplates/api-routes.ts
LOWAnomalyLOW
templates/api-routes.ts
No malicious behavior is evident in this fragment. The code is ordinary workflow and actor HTTP glue, but it presents medium security risk if these endpoints are publicly reachable without authentication and ownership checks. In particular, unvalidated runId and actorId values could enable workflow stream disclosure, actor state disclosure, or unauthorized actor event submission. Inputs should be schema-validated and endpoints should enforce authentication, authorization, size limits, and bounded startIndex values.
Confidence: 96%Severity: 62%
Audit Metadata