endurance-coach
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreference/assessment.md
LOWAnomalyLOW
reference/assessment.md
The visible text is benign training-plan guidance, but it recommends executing an unpinned latest npm package via `npx -y`. That creates a significant supply-chain exposure because arbitrary code from a mutable package release may run with the user’s privileges and may access Strava-related data. No direct malware behavior is demonstrated in the supplied fragment, and the package implementation is not available for verification.
Confidence: 95%Severity: 55%
Audit Metadata