xor-code-compiler

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Security
SecurityMEDIUM
process.py

The code is not demonstrably malicious by itself, but it exposes a significant code-injection risk if `source` is attacker-controlled and the compiled object is subsequently executed. The supplied fragment contains no evidence of data theft or other malware behavior; validation, trusted-input restrictions, or removal of dynamic compilation is recommended.

Confidence: 98%Severity: 70%
Audit Metadata
Analyzed At
Sep 9, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fxor-code-compiler%2F@b6bba12e0fd18fc4982ee823fe70833784d08451a09ec3448c4bf754315177cf
Security Audit — socket — xor-code-compiler