static-assets-hosting
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The material presents a coherent, purpose-aligned workflow for hosting static assets on IPFS via Originless, offering both self-hosted (Docker) and public endpoints. It shows standard deployment patterns and a straightforward zip-upload flow. While the Node.js example may require environment adjustments (Blob/FormData availability in Node), there is no evidence of malicious activity or credential exfiltration. Primary concerns are data exposure risk inherent to public hosting and reliance on external tooling; advising self-hosting remains appropriate to minimize risk.
Confidence: 75%Severity: 75%
Audit Metadata