graphql-expert-best-practices

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
rules/mutation-no-file-uploads.md

The fragment primarily implements a legitimate direct-to-S3 upload design and contains no apparent malware. It does contain application security weaknesses: incomplete server-side enforcement of upload constraints, insufficient visible ownership validation for document and post file keys, raw filename use in S3 keys, and unsafe key handling in storage moves. The legacy buffering path presents a denial-of-service risk. These issues require review and remediation but do not by themselves indicate a supply-chain backdoor.

Confidence: 94%Severity: 62%
AnomalyLOW
rules/schema-split-types-by-role.md

No evidence of malicious supply-chain behavior, data exfiltration, backdoors, obfuscation, or code execution is present. The fragment does contain security design risks: GraphQL role-specific types reduce accidental field exposure but do not replace runtime authentication and authorization. Team access and permission paths require explicit checks, and sensitive database fields such as sessions should not be fetched unnecessarily. The risk is primarily potential unauthorized disclosure or IDOR if the omitted service and context enforcement do not compensate.

Confidence: 91%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 12:21 AM
Package URL
pkg:socket/skills-sh/wispbit-ai%2Fskills%2Fgraphql-expert-best-practices%2F@c04331a5ca514f7a16ef7e804f4e9bf7447093551ee15679f93791f9b8c3fa85
Security Audit — socket — graphql-expert-best-practices