materialize-docs
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
SecuritySecurityingest-data/webhooks/webhook-quickstart/index.md
MEDIUMSecurityMEDIUM
ingest-data/webhooks/webhook-quickstart/index.md
This is not clearly malicious malware, but it is security-relevant demo code that contains multiple high-risk patterns: eval() on user-controlled schema text, repeated POSTing of generated data to a user-supplied URL, and inclusion of a user-provided secret in both a request header and console logs. If reused outside a tightly controlled educational context, it can function as a credential-exfiltration and arbitrary network-sending utility, so it should be treated as a security warning rather than a safe example.
Confidence: 76%Severity: 72%
Audit Metadata