elixir-security-review

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
references/code-injection.md

The code is security guidance containing explicitly vulnerable examples. Code.eval_string/1 on external input is a critical arbitrary-code-execution pattern, and binary_to_term/1 without [:safe] is unsafe for untrusted data. Dynamic module resolution from input should be replaced by the provided fixed allowlist. The fragment itself shows no malware, exfiltration, persistence, or obfuscation; risk applies if the vulnerable examples are deployed.

Confidence: 98%Severity: 88%
Audit Metadata
Analyzed At
Sep 20, 2026, 09:17 AM
Package URL
pkg:socket/skills-sh/existential-birds%2Fbeagle%2Felixir-security-review%2F@4d3221e60dc470c48428ec6db9e5040d1b8fce6654ff98ed6678cae47029039e
Security Audit — socket — elixir-security-review