hasura-graphql-engine

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
EXAMPLES.md

No evidence of malware, sabotage, credential theft, persistence, obfuscation, or suspicious exfiltration is present. The material is documentation with legitimate Hasura integration examples, but several examples are unsafe if copied directly: client-controlled payment amounts, unrestricted public file uploads, broad metadata permissions, admin-secret exposure risk, and unescaped HTML email content. These are security and design risks rather than malicious supply-chain behavior.

Confidence: 98%Severity: 70%
Audit Metadata
Analyzed At
Sep 15, 2026, 09:24 AM
Package URL
pkg:socket/skills-sh/manutej%2Fluxor-claude-marketplace%2Fhasura-graphql-engine%2F@8a2c307187758c8ad80dbd7b238bef27533e68fe1ae4ad90b080293048e13407
Security Audit — socket — hasura-graphql-engine