setup
Warn
Audited by Socket on Oct 6, 2026
1 alert found:
SecuritySecurityscripts/humane_setup.py
MEDIUMSecurityMEDIUM
scripts/humane_setup.py
No clear evidence of intentional malware is present. There is a command-injection risk: an untrusted or malicious `token_base` configuration/environment value can be inserted into a shell command and executed through `install`. Avoid `shell=True` and pass validated arguments as a sequence; quote or otherwise safely constrain the path.
Confidence: 98%Severity: 72%
Audit Metadata