alipay-enterprise-scenario-integration

Warn

Audited by Socket on Jun 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/validate_codegen.js

No direct evidence that this module itself contains malware (no hardcoded secrets, no obvious data theft/exfiltration, no stealth/persistence). The main security concern is operational: it can execute untrusted code from the scanned target project during preflight (notably via Node requiring discovered files and via running npm/mvn/go/dotnet build/test commands). If targetDir is not fully trusted, this creates a meaningful CI/supply-chain code-execution risk.

Confidence: 66%Severity: 62%
SecurityMEDIUM
SKILL.md
Audit Metadata
Analyzed At
Jun 26, 2026, 09:37 AM
Package URL
pkg:socket/skills-sh/alipay%2Fai%2Falipay-enterprise-scenario-integration%2F@ee8a8efd9c8d0c77c5609cb254931819ebe6500c64484301cd0c4ebf5583be32
Security Audit — socket — alipay-enterprise-scenario-integration