mind-weapon
Warn
Audited by Socket on Jul 25, 2026
1 alert found:
AnomalyAnomalyguides/06-onboarding-flow.md
LOWAnomalyLOW
guides/06-onboarding-flow.md
No clear evidence of intentional malware/backdoors or supply-chain sabotage is visible in the provided fragment. The dominant security concerns are application-level: (1) high-risk SSRF potential from server-side URL scraping without sandboxing/allowlisting (implementation-dependent in scrapeUrl), and (2) prompt/data-injection risk from directly embedding scraped/attachment text into agent context that is then persisted and streamed. Additional concerns include missing SSE rate limiting (abuse/DoS) and potential content-mention/link abuse depending on downstream rendering/sanitization.
Confidence: 44%Severity: 67%
Audit Metadata