pocketbase-best-practices

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
rules/auth-impersonation.md

The code is a legitimate administrative impersonation example and contains no evident malware or supply-chain attack behavior. Its primary risks are inherent to privileged token handling: superuser credentials, impersonation tokens, and API tokens must remain server-side, be access-controlled, audited, and protected from leakage. The hardcoded localhost URL and lack of explicit validation or authorization around user identifiers are deployment and access-control concerns, but no malicious behavior is shown.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/greendesertsnow%2Fpocketbase-skills%2Fpocketbase-best-practices%2F@649b7e3ee1825738751fe6496c9699ed11dd263bf511cce3d9e7da68121159ac
Security Audit — socket — pocketbase-best-practices