owasp-top-10

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ssrf.md

The fragment documents SSRF and includes an intentionally vulnerable example where user input reaches fetch() without validation. The secure example demonstrates an allow-list mitigation but is not comprehensive against all SSRF bypasses. It contains no evidence of supply-chain malware or malicious intent; the primary security concern is the explicitly shown vulnerable pattern if copied into an application.

Confidence: 99%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:10 PM
Package URL
pkg:socket/skills-sh/nickcrew%2Fclaude-cortex%2Fowasp-top-10%2F@be9bcca91a44de1b64fc9caa8c5df612c97aa133209ad2d334593eb83f3c3cd0
Security Audit — socket — owasp-top-10