volcengine-sdk-generator

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Anomaly
AnomalyLOW
references/sdk-integration-php.md

No direct indicators of intentional malware are present in the provided fragment; it appears to be a legitimate SDK usage example. However, it includes multiple high-impact security anti-patterns—disabling TLS certificate verification, forcing plaintext HTTP, routing through an HTTP proxy, and enabling debug logging to a file—which can materially increase exposure to MITM interception and sensitive data leakage (especially for authenticated requests/headers/tokens depending on SDK logging). Review the underlying SDK/credential-provider implementations and ensure debug logging and transport security are correctly configured for production.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Jul 28, 2026, 02:49 PM
Package URL
pkg:socket/skills-sh/volcengine%2Fvolcengine-skills%2Fvolcengine-sdk-generator%2F@a4ccd3a8fd7b1a6b72b1559f8c66ea3f1d1b715dea72cbfaeff4f6722d8e15d2
Security Audit — socket — volcengine-sdk-generator