appsec
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
SecuritySecurityevals/cases/bad-appsec-committed-secrets/NOTES.md
MEDIUMSecurityMEDIUM
evals/cases/bad-appsec-committed-secrets/NOTES.md
No executable malicious code is shown; the fragment provides no runtime sinks or source-to-sink behavior. However, it explicitly describes a repository state that would contain extremely sensitive credentials and an SSH private key PEM block committed into source control—an inherently critical security risk due to credential exposure. Claims about middleware or scanner rule silencing do not address the core risk of committed secrets.
Confidence: 75%Severity: 88%
Audit Metadata