alipay-enterprise-scenario-integration
Warn
Audited by Socket on Jun 26, 2026
2 alerts found:
AnomalySecurityAnomalyscripts/validate_codegen.js
LOWAnomalyLOW
scripts/validate_codegen.js
No direct evidence that this module itself contains malware (no hardcoded secrets, no obvious data theft/exfiltration, no stealth/persistence). The main security concern is operational: it can execute untrusted code from the scanned target project during preflight (notably via Node requiring discovered files and via running npm/mvn/go/dotnet build/test commands). If targetDir is not fully trusted, this creates a meaningful CI/supply-chain code-execution risk.
Confidence: 66%Severity: 62%
SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Audit Metadata