spring-ai-integration

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
examples/bad-ai-service.java

No overt backdoor/execution malware is visible in this fragment, but the module is security-relevant due to (1) a hardcoded API key in source code and (2) direct transmission of potentially sensitive order/PII data to an external AI service using unparameterized string-concatenated prompts. The code also permissively parses untrusted remote output and silently swallows exceptions without observability, which increases the likelihood of undetected prompt-injection-driven misinformation/data disclosure and reduces incident response effectiveness.

Confidence: 70%Severity: 82%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/rrezartprebreza%2Fspring-boot-skills%2Fspring-ai-integration%2F@1006b32c63a34c006aa4dbf0da9ca0d5dfe4be81927584270d705b0a55df2671
Security Audit — socket — spring-ai-integration