testing-webapps
Warn
Audited by Socket on Sep 13, 2026
1 alert found:
AnomalyAnomalyscripts/with_server.py
LOWAnomalyLOW
scripts/with_server.py
The code is a legitimate server orchestration and command-running utility with no clear evidence of malware or supply-chain sabotage. It has a significant command-injection risk because untrusted --server values are executed via shell=True, and it can intentionally execute arbitrary commands supplied as the positional command. Restrict use to trusted input, avoid shell=True where possible, and consume or redirect server output to prevent pipe-buffer blocking. The fragment also appears syntactically incomplete at the final call.
Confidence: 98%Severity: 68%
Audit Metadata