local-first

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/client-storage.md

The visible fragment does not indicate malware or supply-chain sabotage. It contains one concrete security issue: SQL injection in `insertTodo` because `todo.id` and `todo.title` are interpolated directly into SQLite SQL. The PGlite and SQLite search examples use parameterization correctly. OPFS and IndexedDB operations are origin-scoped browser storage operations, with no evident data exfiltration or malicious behavior. `safeWrite` also lacks a bounded retry strategy and could repeatedly recurse under persistent quota failure.

Confidence: 98%Severity: 62%
SecurityMEDIUM
references/multi-tenant.md

No clear malware or supply-chain backdoor is present. The code is readable and purpose-consistent, but it has significant multi-tenant security weaknesses: injection-prone filter construction, unrestricted table selection, incomplete demonstrated RLS enforcement, client-forged audit attribution, and non-guaranteed local data deletion. These issues require remediation before relying on the patterns for tenant isolation or revocation.

Confidence: 96%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Flocal-first%2F@ad3021eea0357231247ea8e130e6fbb34c72a6f39c035643fa381964d4d40ee6
Security Audit — socket — local-first