owasp-api-security-top-10

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/api3-broken-object-property-authorization.md

The file is a security guidance document describing mass-assignment/overposting and sensitive-field exposure (API3:2023). The 'Wrong' examples show high-risk patterns: (1) iterating over request.json and setattr -> db.session.commit() enables unauthorized modification of privileged fields; (2) returning user.__dict__ leaks internal/sensitive data. The 'Right' examples show correct mitigations (explicit request/response schemas and role-based filtering). The document itself is not malicious, but the insecure code patterns, if present in production code, represent significant security vulnerabilities that should be remediated as recommended.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/yariv1025%2Fskills%2Fowasp-api-security-top-10%2F@03beceb521f77eb501462cf1fe92a1a940a5c57a