local-ai-app-integration
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecurityevals/evals.json
MEDIUMSecurityMEDIUM
evals/evals.json
The evaluation payload indicates high-risk intent around local/offline model deployment, vendor binaries, and removal of authentication barriers. While the content is a data structure describing prompts (not executed code), adopting these prompts in tooling could enable supply-chain manipulation, data leakage, or backdoors. Recommend strict governance, code review, and explicit authorization before enabling offline/inlined inference or vendor binaries in any consumer-facing or enterprise product.
Confidence: 52%Severity: 78%
Audit Metadata