builder-smoke-test
Fail
Audited by Socket on May 17, 2026
1 alert found:
MalwareMalwareassets/template/src/mastra/index.ts
HIGHMalwareHIGH
assets/template/src/mastra/index.ts
This module is mostly standard server configuration but contains a high-impact confidentiality violation: when SMOKE_TEST_COOKIE_LEAK is enabled, it exposes an endpoint that returns the request’s Cookie header verbatim in the HTTP response. If reachable in any real environment (including staging/production via misconfiguration), it enables cookie/session exfiltration. No other strong malware indicators are evident in this snippet, but the included behavior is sufficiently dangerous to treat as malicious or backdoor-like debug functionality.
Confidence: 70%Severity: 100%
Audit Metadata