builder-smoke-test

Fail

Audited by Socket on May 17, 2026

1 alert found:

Malware
MalwareHIGH
assets/template/src/mastra/index.ts

This module is mostly standard server configuration but contains a high-impact confidentiality violation: when SMOKE_TEST_COOKIE_LEAK is enabled, it exposes an endpoint that returns the request’s Cookie header verbatim in the HTTP response. If reachable in any real environment (including staging/production via misconfiguration), it enables cookie/session exfiltration. No other strong malware indicators are evident in this snippet, but the included behavior is sufficiently dangerous to treat as malicious or backdoor-like debug functionality.

Confidence: 70%Severity: 100%
Audit Metadata
Analyzed At
May 17, 2026, 10:14 AM
Package URL
pkg:socket/skills-sh/mastra-ai%2Fmastra%2Fbuilder-smoke-test%2F@30e3e9c76c15e8d81fce05258f38a6be33fbcf42