local-first
Audited by Socket on Sep 15, 2026
2 alerts found:
AnomalySecurityThe visible fragment does not indicate malware or supply-chain sabotage. It contains one concrete security issue: SQL injection in `insertTodo` because `todo.id` and `todo.title` are interpolated directly into SQLite SQL. The PGlite and SQLite search examples use parameterization correctly. OPFS and IndexedDB operations are origin-scoped browser storage operations, with no evident data exfiltration or malicious behavior. `safeWrite` also lacks a bounded retry strategy and could repeatedly recurse under persistent quota failure.
No clear malware or supply-chain backdoor is present. The code is readable and purpose-consistent, but it has significant multi-tenant security weaknesses: injection-prone filter construction, unrestricted table selection, incomplete demonstrated RLS enforcement, client-forged audit attribution, and non-guaranteed local data deletion. These issues require remediation before relying on the patterns for tenant isolation or revocation.