cloudflare-zero-trust-access

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
templates/multi-tenant.ts

No direct evidence of malicious code or supply-chain malware is present. The primary risks are severe missing authorization on tenant administration endpoints, exposure of tenant configuration, lack of input validation, and dynamic use of a database-controlled Cloudflare Access domain. The fragment is also syntactically incomplete. SQL queries use parameter binding, but the application should protect admin routes, validate tenant fields and allowed domains, avoid returning sensitive configuration, and avoid exposing internal error messages.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:03 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fcloudflare-zero-trust-access%2F@183d92db4da89fc881213e8bf9e07aeead7b8cef580c03bc03e71d13b4b37cb0
Security Audit — socket — cloudflare-zero-trust-access