moai-baas-clerk-ext

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill narrative and code samples present a coherent enterprise authentication platform concept with Context7 integration and WebAuthn. However, there are critical security concerns: privileged credentials (CLERK_SECRET_KEY) appear to be used in frontend/client-side code to call Clerk APIs, creating a high-risk exposure and misalignment with secure production architectures. Organization invitation and WebAuthn flows exacerbate risk if client-side secrets are trusted for authorization. Recommendation: remove secrets from client code, migrate privileged actions to a secure backend that issues short-lived tokens with proper RBAC, and implement server-side validation and audit logging for sensitive operations. Until remediation, treat as suspicious for production use with elevated security risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:09 AM
Package URL
pkg:socket/skills-sh/ajbcoding%2Fclaude-skill-eval%2Fmoai-baas-clerk-ext%2F@e5b9018c873293c997ee04343b61b5d62ae89129