fusionauth

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This Skill documentation is coherent and aligned with its stated purpose: integrating FusionAuth via the official TypeScript SDK and REST APIs. It asks for expected environment variables (FusionAuth URL, API key, app/tenant IDs), instructs use of the official npm package, and shows appropriate server-side webhook verification. There are no indicators of malicious behavior, hidden data exfiltration, obfuscated code, or download-and-execute supply-chain tricks in the provided content. Main risk is standard: the API key is powerful and must be protected by the developer (store env files securely, pin and audit npm dependencies). Overall this appears benign for its intended purpose.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 01:06 AM
Package URL
pkg:socket/skills-sh/oscarangulo%2Fskills%2Ffusionauth%2F@82524f0f9e30b1f256af772b0fcaf9e84f747088