api-design
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalyevals/files/legacy-endpoints.md
LOWAnomalyLOW
evals/files/legacy-endpoints.md
No malicious behavior or obfuscated code is present in the supplied endpoint inventory. The documented API has notable security and integrity risks if controls are not implemented elsewhere, especially unrestricted collection reads, missing-input side effects, silent SKU overwrites, negative quantities, permissive reservation responses, and a long-running export that conflicts with load-balancer timeouts. Confidence is limited because router implementation and authentication details were not provided.
Confidence: 96%Severity: 62%
Audit Metadata