graphql-architect
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalyREFERENCE.md
LOWAnomalyLOW
REFERENCE.md
No malicious behavior or supply-chain malware is evident. The main security concerns are authorization gaps in subscriptions, unrestricted user-status events, incomplete role enforcement, insufficient pagination validation, and a DataLoader/Redis bug that returns null for newly fetched users. These issues warrant remediation before production deployment, but the code does not show credential theft, exfiltration, reverse shells, obfuscated payloads, or destructive actions.
Confidence: 94%Severity: 58%
Audit Metadata