fresh-deploy-friction
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalyscripts/run.sh
LOWAnomalyLOW
scripts/run.sh
The script appears to be an explicit Docker development/deployment harness rather than malware. The primary security flaw is accidental disclosure of forwarded API keys through the status echo. Remove secret values from the diagnostic output, for example by printing only variable names or a redacted marker. Treat the Dockerfile/image and any executed commands as trusted inputs because they receive forwarded credentials and repository contents.
Confidence: 98%Severity: 58%
Audit Metadata