agentic-evals
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalysrc/regressions.py
LOWAnomalyLOW
src/regressions.py
The code is an otherwise readable regression-audit utility with no direct evidence of malware or data exfiltration. Its significant security risk is intentional command execution from the JSON field fail_before_fix.proof_command, combined with an uncontrolled working directory. This is acceptable only when registry contents are trusted and reviewed; untrusted registry data could enable arbitrary command execution and path escape. The fragment also appears incomplete syntactically at the end.
Confidence: 97%Severity: 68%
Audit Metadata