fullstack-workspace-init

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/add-api-collection.py

No clear malicious behavior or supply-chain payload is present. The code is an ordinary project scaffolding generator, but it has a potential path traversal issue because the collection name is used in filesystem paths without strict validation. The generated API also has likely tenant-authorization and organization-mutation risks that should be fixed by validating collection names, deriving organization from authenticated context, and excluding organization from update DTOs.

Confidence: 93%Severity: 58%
AnomalyLOW
scripts/add-frontend-app.py

The fragment is intended as a frontend app scaffolding utility but is incomplete and likely syntactically or logically corrupted. If repaired and executed, it has a meaningful filesystem security issue because the app name permits path traversal or absolute-path writes, and it has an unsafe source-generation issue because the name is inserted into TSX without escaping. No direct malicious behavior is evident in the supplied code.

Confidence: 97%Severity: 63%
Audit Metadata
Analyzed At
Sep 16, 2026, 05:11 AM
Package URL
pkg:socket/skills-sh/shipshitdev%2Fskills%2Ffullstack-workspace-init%2F@e1aa3d51b5cb0e78ee72bcf8652a06cb90699d4351842e17d5492b9a3cf6abea
Security Audit — socket — fullstack-workspace-init