dingtalk-aitable

Warn

Audited by Socket on Jul 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/aitable_import_via_task.py

No direct evidence of malware (backdoors, obfuscation-driven payloads, or credential theft) is present in this Python snippet. However, the tool performs high-impact operations: it executes an external `dws` executable provided via `--dws` (supply-chain/control-plane risk) and uploads complete local file bytes to an `uploadUrl` returned by that external command without validating the destination (exfiltration risk if `dws` is compromised or manipulated). Overall, this is likely a legitimate import orchestrator but with moderate security risk centered on external trust and unvalidated upload destinations.

Confidence: 70%Severity: 52%
Audit Metadata
Analyzed At
Jul 20, 2026, 11:21 AM
Package URL
pkg:socket/skills-sh/dingtalk-real-ai%2Fdingtalk-workspace-cli%2Fdingtalk-aitable%2F@3fefb8b2e1b80df3d532f4e9c2262af03150fc87fa2b5e24b91de0ee4b155015
Security Audit — socket — dingtalk-aitable