extractor-quality-check
Audited by Socket on Mar 17, 2026
1 alert found:
Obfuscated FileThis module is functional for orchestration and learning of remediation actions, but contains a high-risk pattern: executing job-supplied shell commands via bash -lc without sanitization or an allowlist. That is the primary security concern (potential RCE and subsequent data exfiltration or persistence). Secondary concerns are unredacted persistence of PDF metadata and command outputs to local files and an external memory/taxonomy backend. No hard-coded credentials or obvious obfuscated backdoors are present in this fragment. Recommended mitigations: enforce a strict allowlist of permitted skills/commands or avoid shell invocation (use list args), run remediation in constrained sandboxes/containers with least privilege, redact or minimize data sent to MemoryClient, authenticate and restrict memory/taxonomy backends, protect file paths and apply access controls, and add explicit validation and auditing of job sources.