freshrss

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/api_doc.md

No clear evidence of covert malware in this fragment (no persistence, obfuscation, or nonstandard malicious behavior). The dominant concern is security hygiene and abuse potential: a hardcoded credential-like Authorization value and inclusion of a state-changing unsubscribe request. If such logic appeared inside an actual dependency or automation, it could facilitate unauthorized account manipulation or credential exposure; additional context is needed to determine whether it is merely documentation/example code or part of an installed package.

Confidence: 55%Severity: 52%
Audit Metadata
Analyzed At
Aug 8, 2026, 02:08 AM
Package URL
pkg:socket/skills-sh/wmy2981%2Fskills%2Ffreshrss%2F@4dd2c6364b9ac2f2036478de4d6d5a4ada7f468753554f20869e1304bb4fd1d2
Security Audit — socket — freshrss