cloudflare

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
references/pages-functions/patterns.md

No clear malware/backdoor mechanisms are present in the shown code (no eval/dynamic execution, no process spawning, no destructive actions). However, there is a suspicious hardcoded external webhook call in a background task (fetch to an external domain), which can enable data exfiltration or tracking. Additional security risks include overly permissive CORS and an unvalidated file upload path using client-controlled filenames. Overall, treat this as a potential supply-chain security risk and verify the webhook behavior and whether any sensitive data is sent.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:08 AM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fcloudflare%2F@0401989fbbaa6ce8f52b1e99aee4e839c51dc104