hono-routing

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
templates/validation-zod.ts

The fragment does not show clear malware or supply-chain sabotage. It contains several significant application-security weaknesses: sensitive card-number logging, ineffective Bearer authentication, a login endpoint without credential verification, an incomplete password-change implementation, permissive parsing, and likely missing authorization around user updates. These issues are security-relevant if the handlers are reachable in production, but there is no evidence of malicious intent in the code shown.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 12:04 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fhono-routing%2F@548f8717e93d5fba88c09c23f3a8ce6b5048dc40e2c86b2933f99bc6c890bafa
Security Audit — socket — hono-routing