create-pdf-fixture
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalyrun.sh
LOWAnomalyLOW
run.sh
The script appears to be a development utility for generating PDF fixtures. It contains no direct indicators of malicious behavior, but it executes a remote Git repository through uv and sources a local .env file as shell code. Those operations create meaningful supply-chain and local-code-execution risks if the repository or .env file is compromised. Pinning the repository to a reviewed commit and avoiding executable environment-file sourcing would reduce risk.
Confidence: 96%Severity: 55%
Audit Metadata