workflow-devkit

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/api-routes.ts

No malicious behavior is evident in this fragment. The code is ordinary workflow and actor HTTP glue, but it presents medium security risk if these endpoints are publicly reachable without authentication and ownership checks. In particular, unvalidated runId and actorId values could enable workflow stream disclosure, actor state disclosure, or unauthorized actor event submission. Inputs should be schema-validated and endpoints should enforce authentication, authorization, size limits, and bounded startIndex values.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:27 PM
Package URL
pkg:socket/skills-sh/johnlindquist%2Fclaude%2Fworkflow-devkit%2F@fd32c615a0971002e923c0b06290050d6f95b7c02fff8504813c2f3f1e7ddf01
Security Audit — socket — workflow-devkit