litreview
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyscripts/citation_tracker.py
LOWAnomalyLOW
scripts/citation_tracker.py
No evidence of intentional malware, data exfiltration, reverse shells, cryptomining, credential theft, or sabotage is present. The principal security defect is unsanitized session-name path construction, which can enable path traversal or arbitrary-path access/write under the process account. Input validation, confinement to SESSIONS_DIR, and safer atomic/permission-controlled writes are recommended.
Confidence: 98%Severity: 55%
Audit Metadata