autoreview
Warn
Audited by Socket on May 29, 2026
1 alert found:
AnomalyAnomalyscripts/test-review-harness
LOWAnomalyLOW
scripts/test-review-harness
This module is a security review harness that generates a “malicious” Node.js fixture containing clear high-risk behavior (execSync-based destructive rm -rf using interpolated input and direct password disclosure). The bash harness itself only writes the fixture and runs a local reviewer, but because the package includes/produces destructive and credential-leaking code, it poses a moderate-to-high supply-chain/security risk if misexecuted or distributed without strict controls.
Confidence: 74%Severity: 62%
Audit Metadata