llm-integration

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
references/advanced-patterns.md

The fragment does not show clear malicious intent or malware. It contains a high-impact unsafe-deserialization risk because pickle.load processes cache contents without trust or integrity validation, and a path traversal risk because session_id is used directly in a filename. Cache files should use a safe serialization format or authenticated data, and session IDs should be strictly validated or mapped to safe filenames.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:54 PM
Package URL
pkg:socket/skills-sh/martinholovsky%2Fclaude-skills-generator%2Fllm-integration%2F@6461dfbf6ea4db42b241c42d71dd7f2862ff3ed80b0e747350193dcea90cca65
Security Audit — socket — llm-integration