prava-sdk-integration

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
references/session-api-reference.md

The visible fragment appears to implement a payment-session polling and integration guide rather than malware. It contains a sensitive credential flow: custom-mode results expose a token, dynamic CVV, and expiry fields for subsequent processor submission. This is a significant security and compliance boundary, but the code includes no visible obfuscation, command execution, secret harvesting, or covert exfiltration. Trust in the external payment domain and safety of omitted request/call-site code require independent verification.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
Sep 19, 2026, 09:58 PM
Package URL
pkg:socket/skills-sh/prava-payments%2Fprava-skills%2Fprava-sdk-integration%2F@3f586525526f2f3c1149c7df8631ef15db680d34d22114e25f3bdcefd11997fd
Security Audit — socket — prava-sdk-integration