review-auth

Warn

Audited by Socket on Aug 16, 2026

1 alert found:

Security
SecurityMEDIUM
evals/evals.json

The combined evidence shows multiple critical authorization weaknesses alongside a clearly implementable path to remediation. Highest priority: enforce ownership checks on all read/update endpoints that operate on per-user data (especially GET /orders/:orderId and PUT /users/:id), and restrict or validate role changes to prevent privilege escalation. Mitigate JWT algorithm confusion by pinning allowed algorithms and aligning token issuance/verification. Maintain secure session cookies and ensure HTTPS deployment. Overall security risk remains significant until these mitigations are applied, with IDOR and privilege-escalation being the primary concerns.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Aug 16, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/mshindi-labs%2Fagent-skills%2Freview-auth%2F@fa47968d0fa60ef5c60333e715eeadf47ea6f120a3a82bd594037084f93fa8da
Security Audit — socket — review-auth