taruvi-app-developer

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/function-scenarios.md

The visible code is primarily ordinary application integration code and does not indicate intentional malware. The public payment webhook presents a significant application security and fraud risk because it records caller-controlled payment events without visible authentication, signature validation, replay protection, or input validation. The OpenAI integration intentionally transmits prompts and uses a stored secret with the official API; this is not inherently malicious but may have privacy and cost implications. Assessment is limited to the shown fragments.

Confidence: 94%Severity: 62%
AnomalyLOW
scripts/export-backend.js

The code appears to be a legitimate backend export utility rather than malware. It intentionally downloads an application package, including secrets, and extracts it locally. Security concerns include sending an API key to an unvalidated user-supplied URL, exposing the key in process arguments, allowing HTTP, recursively deleting the output directory, and extracting an untrusted archive without explicit path-traversal or symlink defenses. No clear malicious payload, persistence, data theft from the local system, or reverse shell is present in this fragment.

Confidence: 97%Severity: 66%
Audit Metadata
Analyzed At
Sep 16, 2026, 11:55 AM
Package URL
pkg:socket/skills-sh/taruvi-ai%2Ftaruvi-skills%2Ftaruvi-app-developer%2F@c7fbe283446c9e9aaa47da0fe5ebd1e675d9e78ddefaaa09d6f2a4cbf76b5c2a
Security Audit — socket — taruvi-app-developer