pachca-bots

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/link-unfurling.md

The described workflow presents a plausible data leakage risk via link-driven unfurling. It is not inherently malicious, but requires strong safeguards: explicit user consent, strict URL validation, minimal data exposure, least-privilege access for the unfurl bot, explicit allowlists, robust auditing/logging of previews, and clear governance over which domains can receive previews. Implement authentication for webhook/invocation, input/output sanitization, and rate limiting to reduce abuse potential.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:33 AM
Package URL
pkg:socket/skills-sh/pachca%2Fopenapi%2Fpachca-bots%2F@95aba23c6cd256c5e509405c83ea895bcdb8c165
Security Audit — socket — pachca-bots