sharp-edges

Warn

Audited by Socket on Aug 20, 2026

1 alert found:

Security
SecurityMEDIUM
references/auth-patterns.md

The fragment provides severe authentication and authorization anti-patterns: IDOR via untrusted user_id object lookups, MFA bypass risks due to frontend-only enforcement and weak/spoofable device-token derivation, and account takeover via predictable, non-invalidated recovery codes with effectively unlimited guessing attempts. There is no clear evidence of supply-chain malware (e.g., payload execution, persistence, exfiltration, or obfuscation); the risk is extremely high from broken authz/authn design if implemented as shown.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Aug 20, 2026, 12:51 PM
Package URL
pkg:socket/skills-sh/waybarrios%2Fopencode-power-pack%2Fsharp-edges%2F@0b555f34544c5c92e2f2edbb23718cc78d57883bf62f59a20fa7276ace82e35a
Security Audit — socket — sharp-edges