business-logic-security-audit

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
sample-report.md

This audit report documents multiple high-impact business logic and integrity vulnerabilities in a trading platform: webhook signature bypass, race conditions enabling double-spend, KYC state machine bypass, trusting client-supplied exchange rates, insecure token storage on mobile, OAuth deep-link interception, input validation gaps, and information disclosure in mobile bundles. These are not indicators of malware but represent severe supply-chain/security issues that can enable fraud, account takeover, and regulatory violations. Immediate remediation is recommended for the critical items (webhooks, transactional atomicity, KYC authorization) and urgent fixes for high-severity mobile and rate-trust issues.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 13, 2026, 04:03 PM
Package URL
pkg:socket/skills-sh/rigAITe%2Fbusiness-logic-audit%2Fbusiness-logic-security-audit%2F@98b022bff5ea2c267e7520b0e61a362be232c200