frontend-react-router-best-practices

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
rules/route-auth-middleware.md

The code is an authentication and authorization example, not malware. It contains a definite implementation error because authenticate() uses await without async. More importantly, the session cookie configuration does not visibly specify signing secrets, creating a potentially critical authentication-bypass risk if sessions are not integrity-protected by framework defaults. MFA timestamp validation should reject future timestamps, and state-changing actions should include explicit CSRF protection. Verify session-cookie signing/encryption and correct middleware async behavior before using this pattern.

Confidence: 94%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:59 PM
Package URL
pkg:socket/skills-sh/sergiodxa%2Fagent-skills%2Ffrontend-react-router-best-practices%2F@500b3625e4d90257b7bf35da07ad7b6add755b6f6ca6a61b40a06a422d8a96b6
Security Audit — socket — frontend-react-router-best-practices