expression-compiler
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalycalculate.py
LOWAnomalyLOW
calculate.py
This is a dynamic-code compilation helper and is unsafe when called with untrusted input, especially if the returned code object is later evaluated. The fragment alone does not demonstrate malware or direct code execution, but it creates a significant code-injection risk. Input validation, a safe expression parser, or a tightly restricted evaluation design is required.
Confidence: 99%Severity: 68%
Audit Metadata