chatbot-widget-creator

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
api-clients/backend-session.template.ts

The code creates an OpenAI chat session and returns the session.client_secret verbatim to any caller that issues a POST. There is no authentication, rate limiting, or session scoping in the snippet, so deploying this endpoint as-is would expose a sensitive credential to unauthenticated clients and allow abuse or unexpected costs. The snippet does not exhibit signs of intentional malware, but it implements a high-risk secret-exposure pattern that must be fixed before production use.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 03:32 PM
Package URL
pkg:socket/skills-sh/mrowaisabdullah%2Fai-humanoid-robotics%2Fchatbot-widget-creator%2F@3e321d44c349258ae49d763a29941317bd0eaa18