devops

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/browser-rendering.md

No deliberate malware or obfuscation detected. Primary issues are insecure patterns: unvalidated navigation (SSRF risk), unsanitized forwarding of full page HTML to an external AI binding (data leakage), and an unconstrained crawler that re-enqueues links (amplification/loop risk). Recommendations: validate and whitelist target URLs, enforce authentication and authorization for handlers and queue actions, sanitize/redact content before sending to AI services, add domain scoping, deduplication and rate limits to the crawler, instrument limits for Durable Object session lifetime, and secure runtime environment bindings. Treat env.* bindings as secrets and avoid exposing session IDs.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/mrgoonie%2Fclaudekit-skills%2Fdevops%2F@d00dc9218a8231397131fb3dfe642888658b0f1a