engineering-rapid-prototyper
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityreferences/full-stack-integration.md
MEDIUMSecurityMEDIUM
references/full-stack-integration.md
No clear malicious behavior or obfuscated payload is present. The code has material security risks: authenticated users can list or create projects for teams they do not belong to through both tRPC and the create server action, and upload filenames are inserted directly into privileged storage paths without sanitization or upload constraints. Add membership and role checks before every team-scoped operation, sanitize or generate storage object names server-side, validate content type and size, and handle upload failures.
Confidence: 97%Severity: 78%
Audit Metadata