37signals-rails

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/arch-custom-auth.md

The fragment implements a legitimate custom passwordless authentication flow and shows no evidence of malicious supply-chain behavior. It has notable authentication security risks: a globally searched six-digit code without visible rate limiting or uniqueness enforcement, possible email enumeration, tenant-selection assumptions, and unspecified secure-cookie configuration. These issues warrant review and hardening but do not indicate malware.

Confidence: 97%Severity: 63%
AnomalyLOW
references/db-multi-tenancy.md

The code is ordinary Rails multi-tenancy guidance and contains no indicators of malware, data exfiltration, command execution, obfuscation, or sabotage. The primary security concern is missing authorization: any authenticated or unauthenticated caller able to reach these routes may be able to select another account by changing account_id unless authorization is enforced elsewhere. Background-job context preservation also requires verification of the application configuration.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2F37signals-rails%2F@875c8453c9e757687ed2a8349b86c3685842bf507f575bfcbf97c5824326ef92
Security Audit — socket — 37signals-rails