dyno-run-debug
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalydyno/fixtures/.claude/settings.json
LOWAnomalyLOW
dyno/fixtures/.claude/settings.json
No direct malicious code is present; this is a declarative permissions policy. However, it grants broad ability to execute Node/npx/bash-like commands and run file/content inspection utilities (cat/jq/ls) along with Read/Glob/Grep. This is not inherently malicious, but it significantly increases risk if the surrounding system can execute untrusted instructions under these permissions. Review the consumer/runner logic and enforce least-privilege and strict input/command mediation.
Confidence: 60%Severity: 60%
Audit Metadata