expression-compiler

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
calculate.py

This is a dynamic-code compilation helper and is unsafe when called with untrusted input, especially if the returned code object is later evaluated. The fragment alone does not demonstrate malware or direct code execution, but it creates a significant code-injection risk. Input validation, a safe expression parser, or a tightly restricted evaluation design is required.

Confidence: 99%Severity: 68%
Audit Metadata
Analyzed At
Sep 9, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fexpression-compiler%2F@e7653df5820803abd160fd2f6b167b36f3aabd3a70513802ab9c23ecd62b37d3
Security Audit — socket — expression-compiler