litium-developer

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/setup-troubleshooting.md

The fragment is benign troubleshooting documentation with no apparent malware or hidden supply-chain attack. It contains security warnings: sample credentials are exposed in commands, TLS verification is explicitly disabled for local tooling, and cleanup commands can delete databases and project files if run incorrectly. These risks are user-executed configuration and operational risks rather than malicious behavior in the supplied code.

Confidence: 99%Severity: 58%
SecurityMEDIUM
references/extension/framework-patterns.md

No clear evidence of intentional malware/sabotage in the provided fragment. However, it contains high-impact security weaknesses: a likely credential disclosure risk by using a VITE-prefixed OAuth client_secret in browser-side code to request tokens, and a plausible DOM XSS risk from innerHTML populated with route-derived values without visible sanitization. These issues materially increase the security risk of adopting this package in a supply-chain context.

Confidence: 62%Severity: 78%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/litiumab%2Fagent-skills%2Flitium-developer%2F@ca6296022b537102242bcd061debdab9b7c8c4dd3221f350a8f9ceb8da820e5a
Security Audit — socket — litium-developer