team-swarm
Audited by Socket on Sep 3, 2026
1 alert found:
SecurityThis code is primarily a scoring/verification utility, but it contains a high-impact supply-chain / arbitrary code execution mechanism: ScriptScorer dynamically loads and executes Python code from rule_path using spec.loader.exec_module without sandboxing or integrity controls. If rule_path and the loaded file are not strictly trusted and access-controlled, the host application is vulnerable to executing malicious logic. Other concerns include a likely bug in hallucination_check ('threshol' typo) and potential information leakage via printing exception details. No direct malware behaviors (e.g., network exfiltration) are visible in this snippet beyond enabling execution through the plugin mechanism.