12-factor-app

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/admin-repl-access.md

The content is legitimate operational documentation, not malicious package code. It contains no obfuscation, exfiltration, persistence, or sabotage logic. However, production REPL access is intrinsically high privilege and can expose sensitive data or alter application state. The examples should be used only with strong authentication, authorization, auditing, read-only credentials where possible, and carefully controlled change procedures.

Confidence: 98%Severity: 58%
AnomalyLOW
references/parity-developers-deploy.md

No malicious behavior or obfuscated payload is evident. The documentation presents a legitimate developer-operations model, but the example workflow and production-access guidance could create substantial security risk if implemented without protected branches, deployment approvals, environment-scoped secrets, least-privilege Kubernetes RBAC, audited access, and controlled migration procedures.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2F12-factor-app%2F@79c66ff191dc077f848fda40846d1d154d6817a0fdaa1bafd9907e8ba07faa9f
Security Audit — socket — 12-factor-app