testing-webapps

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/with_server.py

The code is a legitimate server orchestration and command-running utility with no clear evidence of malware or supply-chain sabotage. It has a significant command-injection risk because untrusted --server values are executed via shell=True, and it can intentionally execute arbitrary commands supplied as the positional command. Restrict use to trusted input, avoid shell=True where possible, and consume or redirect server output to prevent pipe-buffer blocking. The fragment also appears syntactically incomplete at the final call.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/1git2clone%2Fdotfiles%2Ftesting-webapps%2F@3373f12270427d9b90554689dfc695a76cc58e71d6fb7ad8e070b0150b3eb042
Security Audit — socket — testing-webapps