express-backend-starter

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This skill is a benign, opinionated scaffolding and best-practices guide for building Node.js + Express backends. It requests environment variables and database credentials only insofar as necessary to build and run a backend. There are no download-execute chains, no third-party intermediary endpoints, no instructions to forward credentials to unknown services, and no code obfuscation. Main security considerations are implementation risks by downstream users (secret handling, logging, correct CORS/rate-limiting) rather than malicious intent in the skill itself.

Confidence: 85%Severity: 50%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/codewithhashim%2Fexpress-backend-starter-skill%2Fexpress-backend-starter%2F@f854a018794cb6b5aaa0cd20855003df381b5c59