infra-platform-cloudflare-workers

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
examples/r2.md

The code is ordinary R2 storage example code and shows no clear malicious behavior or obfuscation. However, if deployed without external authentication and authorization, it provides unrestricted object upload, download, listing, and deletion. Direct key handling, client-controlled identity metadata, reliance on Content-Length, and public immutable caching require remediation for production use.

Confidence: 98%Severity: 78%
AnomalyLOW
examples/routing.md

No evidence of malicious supply-chain behavior or obfuscation is present. The code is ordinary Cloudflare Workers example material. Security risk is primarily from incomplete production controls: unauthenticated arbitrary R2 uploads, unauthenticated queue submission, weak pagination validation, and insufficient type validation for AI prompts. These should be addressed before exposing the examples publicly in production.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:58 PM
Package URL
pkg:socket/skills-sh/agents-inc%2Fskills%2Finfra-platform-cloudflare-workers%2F@36a81e722cb7ed5c37901f7411ca2a877edf16d77797bbec3d081ca4aeb8b309
Security Audit — socket — infra-platform-cloudflare-workers