sanity-best-practices

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/migration-html-import.md

The code is primarily legitimate documentation for HTML-to-Portable-Text migration and contains no clear malware or intentional sabotage. It does contain a meaningful server-side request risk in the image upload helper because imported image URLs are fetched without validation or resource controls. Validate allowed protocols and destinations, block private and link-local addresses, enforce response-size and timeout limits, verify content type, constrain redirects, sanitize filenames, and validate link schemes before rendering or storing imported content.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:38 AM
Package URL
pkg:socket/skills-sh/sanity-io%2Fagent-toolkit%2Fsanity-best-practices%2F@37081e7ed61cf14fe20d85aa48b7c210d6196864d4e19044207cf947e7b8ff87
Security Audit — socket — sanity-best-practices