golang-observability

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
references/rum.md

No clear malware or deliberate supply-chain attack is present. The code documents expected analytics integrations, but the displayed privacy endpoints have a potentially serious authorization gap because URL-provided user IDs are used for export and deletion without visible access control. Additional risks include inconsistent consent enforcement, trust of client-supplied correlation headers, and transmission of potentially sensitive order data to third parties. These risks are conditional on absent middleware or surrounding authorization not shown in the fragment.

Confidence: 96%Severity: 70%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:39 PM
Package URL
pkg:socket/skills-sh/samber%2Fcc-skills-golang%2Fgolang-observability%2F@ee389b5464ff09d58e974da6d3b18dc96e6b12098fb85d407aa178cdedcf0d60
Security Audit — socket — golang-observability