metaverse-expert

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
references/EXAMPLES.md

No clear malware or intentional supply-chain attack is evident. The fragment contains significant multiplayer security weaknesses: client-controlled identity and avatar data, client-authoritative movement, unvalidated interaction and voice messages, a potentially exception-producing target lookup, and placeholder NFT authorization that always grants ownership. These issues require remediation before production use, but the code does not show credential theft, exfiltration, reverse shells, obfuscation, or destructive behavior.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Sep 11, 2026, 05:14 AM
Package URL
pkg:socket/skills-sh/personamanagmentlayer%2Fpcl%2Fmetaverse-expert%2F@1cac1ace120525721327db22543c45fa6c2ea76df3046893ca8b2bd3cc8251db
Security Audit — socket — metaverse-expert