bookkeeping
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalytests/test_index.py
LOWAnomalyLOW
tests/test_index.py
No direct malicious functionality (e.g., network exfiltration, credential theft, or system command execution) is evident in the shown snippet. The key security concern is the tier-2 test’s dynamic runtime import and execution of an external kg.py discovered via environment variables and default home/workspace paths. In untrusted or tampered environments, this mechanism could run attacker-controlled code during testing. Review the implementations of bookkeeping.cmd_index and the external kg.py source and ensure kg.py discovery is constrained/verified in real deployments.
Confidence: 60%Severity: 60%
Audit Metadata