trufflehog
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyreferences/custom-detectors.md
LOWAnomalyLOW
references/custom-detectors.md
The fragment is primarily legitimate trufflehog scanning documentation and contains no evident malware or obfuscated malicious payload. However, the custom verification configuration creates a high-impact secret disclosure path because captured tokens are POSTed to an external endpoint and TLS verification is explicitly disabled. Treat the endpoint as trusted only after independent validation, remove unsafe: true, and protect or avoid storing scan results in shared temporary locations.
Confidence: 98%Severity: 68%
Audit Metadata