software-security-appsec

Warn

Audited by Socket on Sep 23, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
assets/web-application/template-authorization.md

The fragment is a legitimate authorization template and shows no evidence of malware or intentional supply-chain compromise. It contains several security-relevant correctness issues, especially the missing getRolePermissions import, the missing requireAnyPermission import in the posts route, policy-order behavior that can produce unintended denials, insufficient null/type handling in ownership checks, and direct use of request bodies in database writes. These issues should be fixed and authorization behavior tested before production use.

Confidence: 98%Severity: 62%
AnomalyLOW
assets/api/template-secure-api.md

The supplied code is a legitimate Express security template with no evidence of malware, data exfiltration, backdoors, reverse shells, cryptomining, or destructive behavior. The primary security concern is mass assignment in the post create and update handlers because the full request body is persisted despite only selected fields being validated. Use explicit field allowlists or schema strictness and validate deployment-specific proxy, CORS, secret, and logging settings before production use.

Confidence: 98%Severity: 52%
AnomalyLOW
assets/web-application/template-authentication.md

The fragment is an authentication template with no apparent malicious or supply-chain behavior. It has meaningful security weaknesses, especially an unauthenticated IDOR in logout, malformed constant-time login handling, plaintext MFA secret storage, and incomplete hardening around refresh and MFA endpoints. These issues should be corrected before production use.

Confidence: 98%Severity: 67%
Audit Metadata
Analyzed At
Sep 23, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/vasilyu1983%2Fai-agents-public%2Fsoftware-security-appsec%2F@6a14c8d72d92a9ad2c248a5b4cc86d456797455a9db6d4c50ee7b54153d03ea1
Security Audit — socket — software-security-appsec