dev-api-design

Warn

Audited by Socket on Sep 23, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
assets/django-rest/django-rest-complete-api.md

The fragment appears to be ordinary Django REST Framework application code and contains no evident malware or supply-chain attack behavior. The primary risks are insecure example deployment settings, broad authenticated access to the user listing/detail endpoints, exposure of is_admin, and possible information disclosure through exception text. Production deployments should require a strong non-default SECRET_KEY, DEBUG=False, strong database credentials, HTTPS-related settings, and tighter user-data permissions.

Confidence: 98%Severity: 55%
AnomalyLOW
assets/oasdiff-ci.yml

The workflow has no clear malicious payload or data-exfiltration behavior. Its main security concern is the unpinned curl-to-shell installation of oasdiff from a mutable upstream branch, which creates a high-impact supply-chain execution risk if that source is compromised. Pin the installer to a reviewed commit or versioned release and verify checksums or signatures; similarly consider pinning actions to immutable commits. Treat pull-request report content as untrusted when rendering it in summaries. The workflow also has a minor failure-handling issue when the base specification does not exist.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 23, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/vasilyu1983%2Fai-agents-public%2Fdev-api-design%2F@7202f56a592301a6aed634acb6fc581ba4fec953da3d9e6cb8511d3f1a8b8ae3
Security Audit — socket — dev-api-design