web-data-fetching-graphql-urql

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/core.md

The code is benign URQL/React example documentation and contains no evident malware or supply-chain attack behavior. However, AdminPanel exposes process.env.ADMIN_TOKEN through a browser request header when used in client-side code, creating a potentially serious credential disclosure risk. Use server-side proxying or user-scoped authentication instead of embedding an administrative token in frontend code.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:46 PM
Package URL
pkg:socket/skills-sh/agents-inc%2Fskills%2Fweb-data-fetching-graphql-urql%2F@dda50f748184cb7cd0f09cc6bb49390a739b2291f3a5ff6cff4ee17b63142a1f
Security Audit — socket — web-data-fetching-graphql-urql