pudu-openapi-skill

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/pudu-request.go

The code is an API client with no clear malicious behavior. Its primary security risk is the unrestricted custom Hostname option: untrusted callers could redirect authenticated requests and API data to an attacker-controlled HTTPS server. Restrict Hostname to an allowlist or require explicit trusted configuration when used in security-sensitive contexts. Legacy MD5/SHA-1 usage appears protocol-driven, and ignored errors are reliability concerns.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 08:49 AM
Package URL
pkg:socket/skills-sh/pudu-robotics%2Fskills%2Fpudu-openapi-skill%2F@b3e8e926b25a18913e95d82ece2ce80825533fa01aa12acee295601007100aa4
Security Audit — socket — pudu-openapi-skill