ce-nextjs-patterns

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill/documentation describes expected patterns for integrating a storefront SDK with Next.js. I found no evidence of malicious code, remote execution chains, or credential harvesting to third-party domains. The main risks are standard supply-chain considerations from installing an npm package (verify package provenance) and the potential misuse of NEXT_PUBLIC_API_KEY (public exposure if a private key is placed there). Overall the content is coherent with its stated purpose and does not contain indicators of malicious behavior.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/commercengine%2Fskills%2Fce-nextjs-patterns%2F@619d144c3452f49408b7e63850873b820100cf30