brainstorming
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
SecuritySecurityscripts/stop-server.sh
MEDIUMSecurityMEDIUM
scripts/stop-server.sh
The code does not show malware, data exfiltration, or obfuscation. It has a meaningful destructive-file-operation risk: the lexical /tmp prefix check does not guarantee that the resolved path is inside /tmp, and the caller controls the cleanup path. Trusting an unvalidated PID file also permits termination of an arbitrary process accessible to the executing user. Canonicalize and validate the session path, reject traversal, use safer directory checks, and validate the PID and process identity before termination.
Confidence: 98%Severity: 72%
Audit Metadata