kasm
Fail
Audited by Socket on Apr 10, 2026
1 alert found:
Obfuscated FileObfuscated Filereferences/workspace-configuration.md
HIGHObfuscated FileHIGH
references/workspace-configuration.md
No direct malicious code is present; the fragment is documentation/config examples. However, it explicitly instructs enabling passwordless sudo for the default container user and provides a first-launch shell execution mechanism. Combined with rw host bind mounts and optional isolation-weakening overrides, these features materially increase impact if an attacker can influence configuration or gain workspace access. Treat this as a high operational-security configuration surface rather than evidence of packaged malware.
Confidence: 98%
Audit Metadata