engineering-rapid-prototyper

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
references/full-stack-integration.md

No clear malicious behavior or obfuscated payload is present. The code has material security risks: authenticated users can list or create projects for teams they do not belong to through both tRPC and the create server action, and upload filenames are inserted directly into privileged storage paths without sanitization or upload constraints. Add membership and role checks before every team-scoped operation, sanitize or generate storage object names server-side, validate content type and size, and handle upload failures.

Confidence: 97%Severity: 78%
Audit Metadata
Analyzed At
Sep 16, 2026, 06:47 PM
Package URL
pkg:socket/skills-sh/peterhdd%2Fagent-skills%2Fengineering-rapid-prototyper%2F@c63d1c3593d7f17023f2820fd99e7e7c70de137166bab5f2674ef9ef02f3f443
Security Audit — socket — engineering-rapid-prototyper