quality-weapon

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Anomaly
AnomalyLOW
guides/04-five-axis-evaluation.md

The described smells signal high-risk patterns for a software supply chain: unvalidated user input driving critical operations (database, file, shell), missing authentication on routes, and performance anti-patterns that can amplify risk and exposure. No explicit malware is shown, but the combination of insecure data flows and auth gaps warrants urgent remediation: implement robust input validation and parameterization, enforce authentication/authorization on all routes (especially newly added ones), apply proper access controls, introduce pagination and batching to prevent data overexposure, and remove or isolate debugging artifacts. A formal secure-by-default review and automated checks should be instituted to prevent regressions.

Confidence: 58%Severity: 64%
Audit Metadata
Analyzed At
Jul 25, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/jzferrell26%2Fdm-skills%2Fquality-weapon%2F@93f1e8b41b9a5eae43c3a117e11f5cf3fc75b3f6c87e4e41b0e79962f68c49b6
Security Audit — socket — quality-weapon