pua
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
SecuritySecurityreferences/platform.md
MEDIUMSecurityMEDIUM
references/platform.md
The fragment describes a remote-connected PUA feature with silent usage tracking, authenticated API calls, payment processing, local state changes, and runtime installation of a Python dependency. It does not itself show an explicit malware payload, but it creates meaningful privacy, credential exposure, payment, and supply-chain risks. The third-party endpoint and token handling require independent verification before use; telemetry should require explicit consent and the payment and installation flows should be removed or hardened.
Confidence: 95%Severity: 72%
Audit Metadata