static-assets-hosting

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The material presents a coherent, purpose-aligned workflow for hosting static assets on IPFS via Originless, offering both self-hosted (Docker) and public endpoints. It shows standard deployment patterns and a straightforward zip-upload flow. While the Node.js example may require environment adjustments (Blob/FormData availability in Node), there is no evidence of malicious activity or credential exfiltration. Primary concerns are data exposure risk inherent to public hosting and reliance on external tooling; advising self-hosting remains appropriate to minimize risk.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:39 AM
Package URL
pkg:socket/skills-sh/besoeasy%2Fopen-skills%2Fstatic-assets-hosting%2F@650dbc220246bdbecb9ed3b97173cbcc2cfebc95