dx-code-analyzer-run

Warn

Audited by Socket on Sep 3, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
scripts/apply-fixes.js

The code is a straightforward filesystem rewrite utility with no apparent classic malware behaviors (no network, no exec/eval). However, it has a significant supply-chain integrity risk: it can read and overwrite arbitrary local files based solely on attacker-controlled JSON fields (loc.file and fixedCode), with only weak runDir prefix stripping and limited bounds checks. If the results JSON is not fully trusted and produced by the same trusted toolchain, this module can be abused to corrupt or inject code into targeted files and to overwrite sensitive files accessible to the process.

Confidence: 70%Severity: 70%
SecurityMEDIUM
scripts/describe-rule.js

No clear evidence of intentional malware behavior (no network exfiltration, persistence, credential theft, or obfuscated payloads observed). However, the module is security-sensitive because it uses `execSync` with shell command strings that directly interpolate untrusted CLI arguments (`ruleName` and `engine`), including embedding `ruleName` into a `grep -i` pipeline. If an attacker can influence CLI arguments in the execution environment (e.g., via a wrapper/CI job), this could enable arbitrary command execution. Additionally, the provided snippet appears truncated at the end of `isSubsequence()`, so behavior completeness is slightly uncertain.

Confidence: 74%Severity: 86%
Audit Metadata
Analyzed At
Sep 3, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fdx-code-analyzer-run%2F@942cdde239eaa7a9fe4cf17339aaf66e707082091683338824d8cfdf1fffc6d2
Security Audit — socket — dx-code-analyzer-run