rails-expert

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Security
SecurityMEDIUM
REFERENCE.md

No malicious behavior or intentional obfuscation is evident. The code is conventional Rails business logic, but it contains material security risks requiring review: missing visible authorization in GraphQL resolvers, possible order IDOR and data disclosure, unbounded GraphQL pagination, and payment-intent ownership validation. The payment confirmation path should verify the intent belongs to the order and customer before changing payment or order status.

Confidence: 93%Severity: 72%
Audit Metadata
Analyzed At
Sep 23, 2026, 08:06 AM
Package URL
pkg:socket/skills-sh/xgaisystems%2Fclaude-supercode-skills-404kidwiz%2Frails-expert%2F@fdb301471f81a9d966dadffcbfb02f04e6a742c5ce9cef31c3ebafe04a846991
Security Audit — socket — rails-expert