harmonyos-iap-integration

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
references/client-arkts.md

No direct supply-chain malware indicators are evident in the provided fragment (no obfuscation/payload execution, no exfiltration, no backdoor behavior). The dominant security concern is an integrity gap: JWSUtil only decodes the JWS payload and does not verify signatures/authenticity, yet decoded fields are used to make entitlement decisions and to call finishPurchase. Treat this as a trust-boundary weakness requiring proper JWS verification (and/or backend verification) before production use.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Sep 3, 2026, 11:34 PM
Package URL
pkg:socket/skills-sh/makerjackie%2Fharmonyos-skills%2Fharmonyos-iap-integration%2F@e66d308ac180f4cedf9bf956d7e6ea608fd65cf4dfc2e1458bca420081740fb8
Security Audit — socket — harmonyos-iap-integration