cxas-sim-eval

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/fetch_app_data.py

The code appears to be a legitimate API export and local file-management utility, with no clear malware indicators. It has a security risk because ZIP extraction is vulnerable to path traversal when the downloaded archive is untrusted or compromised. Archive members should be validated or extracted using a safe extraction routine that ensures every destination path remains within extract_dir. Confidence is high for the identified issue and low for malicious intent.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/googlecloudplatform%2Fcxas-scrapi%2Fcxas-sim-eval%2F@f28cb7d8c4e5c4772813bceb379ff35d795b4523be6182c52a5aa2630a79afbf
Security Audit — socket — cxas-sim-eval