controller-backend
Fail
Audited by Socket on Feb 16, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This documentation and example code are consistent with the stated purpose (server-side integration of Cartridge Controller). There is no direct evidence of malicious behavior in the provided examples. The only notable supply-chain/safety points are: (1) the Rust example uses a Git-hosted dependency which demands trust in that repository, and (2) the examples rely on api.cartridge.gg as a managed gateway — users should verify and trust that endpoint before routing signing/session flows through it. Follow the documented best practices for secret management. No obfuscated or clearly malicious patterns were found.
Confidence: 80%Severity: 25%
Audit Metadata