cloudflare-vectorize

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
templates/document-ingestion.ts

The code does not show clear malicious intent or supply-chain malware. It is a legitimate document-ingestion Worker, but it exposes unauthenticated ingestion and deletion operations and contains a high-impact SSRF risk through POST /ingest/url. Missing input, URL, size, and resource validation can also enable denial of service and unexpected storage or AI costs. Deployment should require authentication and authorization, restrict outbound URLs and redirects, enforce strict limits and timeouts, validate identifiers and numeric parameters, and isolate deletion by namespace.

Confidence: 97%Severity: 82%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:03 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fcloudflare-vectorize%2F@191254f62104642c444b2545fda8a646238fd5c313921c3a0107f214b92d950d
Security Audit — socket — cloudflare-vectorize