paymeuz-clickuz-master

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This repository is a documentation + reference implementation for Payme.uz and Click.uz integrations in NestJS. It does not contain malware or supply-chain download/execute patterns. The main security considerations are implementation-level: protect secret config variables, avoid logging sensitive webhook payloads in plaintext, implement secure Base64 decoding (Buffer.from(..., 'base64') in Node), handle MD5 verification per provider while safeguarding keys, and implement business logic hooks carefully to avoid unintended side effects. Overall low risk from malicious intent but moderate operational risk if integrated carelessly.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 10:46 AM
Package URL
pkg:socket/skills-sh/idealprojectuz%2Fpaymeuz-clickuz-master-skills%2Fpaymeuz-clickuz-master%2F@e732e4357e4fff26d2c887cf9c5bb25a1e78f2b8