cloudflare-workers-frameworks

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/qwik.md

No evidence of intentional malware or supply-chain sabotage is present. The code is a legitimate Qwik on Cloudflare example, but several application security weaknesses are demonstrated: unauthenticated user APIs, missing authorization on mutations, weak request validation, possible CSRF exposure, and potentially unsafe public caching. These are security design risks rather than malicious behavior. Restrict API and mutation routes with explicit authorization, validate request schemas, add CSRF protections where applicable, avoid SELECT * for public responses, and ensure only non-sensitive data is publicly cached.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:03 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fcloudflare-workers-frameworks%2F@6afeedb9e89eb3ee481af5cd7a1a23644bf5c02a01bbdc8a941d3c16fc37afaa
Security Audit — socket — cloudflare-workers-frameworks