github-pr-review
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
AnomalyAnomalytests/fixtures/pr2373_outcomes.json
LOWAnomalyLOW
tests/fixtures/pr2373_outcomes.json
The supplied excerpts show configuration, portability, information-disclosure, and command-injection risks, especially shell eval of a constructed deployment command, possible secret exposure through command logging and URL query parameters, and traceback disclosure. They do not provide clear evidence of intentional malware or supply-chain sabotage. The hardcoded paths and cloud identifiers appear to be project configuration issues rather than malicious implants.
Confidence: 96%Severity: 57%
Audit Metadata