adk-frontend
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyreferences/project-setup.md
LOWAnomalyLOW
references/project-setup.md
No clear malicious behavior or supply-chain attack is present. The material is setup documentation with a legitimate Botpress API integration. However, the frontend PAT testing pattern is a significant credential-handling risk because a PAT supplied to browser JavaScript is exposed to the user environment and may be leaked through logs or client compromise. The example should be restricted to local testing with a minimally privileged token and replaced in production with a secure server-side authentication flow.
Confidence: 98%Severity: 58%
Audit Metadata