security-auditor

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
evals/evals.json

This controller action is highly vulnerable to SQL injection due to direct interpolation of untrusted request input into a raw DB::select() SQL string. It also introduces a conditional reflected XSS risk because the input is passed to the view without demonstrated safe output handling. No overt malware behavior is evident in the provided fragment; the security concern is primarily injection vulnerabilities.

Confidence: 86%Severity: 90%
Audit Metadata
Analyzed At
Apr 8, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/changgenglu%2Fchanggenglu-blog%2Fsecurity-auditor%2F@19b0b99f298f8df4e24227fd4d44505f1eeba907