code-injection-codegen

Fail

Audited by Socket on May 12, 2026

2 alerts found:

Obfuscated FileMalware
Obfuscated FileHIGH
references/sinks.md

This fragment serves as a defensive reference outlining dangerous runtime sinks across languages. It does not execute code or exfiltrate data by itself. The primary risk is in downstream code that may feed untrusted data into these sinks; secure usage requires input validation, use of safe alternatives, and explicit restrictions on dynamic execution or module loading. No malware detected in the fragment itself.

Confidence: 92%
MalwareHIGH
references/poc-skeleton.md

This file is an exploit/weaponizable PoC skeleton for code-generation context escape leading to arbitrary command execution (RCE). It includes multiple crafted injection payload variants and explicit evidence-collection capabilities (execSync-based command execution, filesystem and environment access). While it may not contain the vulnerable dependency’s actual code-generation implementation, the payloads and execution/evidence mechanisms are sufficiently actionable to be considered high risk and strongly indicative of malicious intent.

Confidence: 78%Severity: 90%
Audit Metadata
Analyzed At
May 12, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/ByamB4%2Ffind-cve-agent%2Fcode-injection-codegen%2F@fbd2aeaee21c7c3be1b8dd4d732cb32c5ac2a40e
Security Audit — socket — code-injection-codegen