opencli-adapter-author
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecurityreferences/api-discovery.md
MEDIUMSecurityMEDIUM
references/api-discovery.md
This fragment is a high-abuse, offensive recon workflow for web API discovery and session-authenticated extraction. It explicitly reads cookies/localStorage/session tokens and CSRF artifacts, searches bundles for Bearer-style credentials, and includes an optional interceptor/MITM fallback to capture live API responses. No classic package supply-chain installation behavior is shown because the snippet is not dependency code; however, the capabilities described are strongly incompatible with trusted software supply-chain modules without strict scoping, permissioning, and auditing.
Confidence: 62%Severity: 82%
Audit Metadata