service-de-channel-activate
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalyreferences/phone-verification.md
LOWAnomalyLOW
references/phone-verification.md
No clear malicious or supply-chain attack behavior is present. The workflow is consistent with WhatsApp phone verification through Salesforce. It presents moderate security risks because the OTP is placed in a query string and command invocation, and because predictable /tmp output files are used without documented secure creation, permissions, or cleanup. Use URL encoding, strict allowlist validation, secure temporary files, and avoid exposing the OTP in shell history or process listings.
Confidence: 95%Severity: 55%
Audit Metadata