fact-extractor
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core extraction workflow is internally coherent, but the data-flow design routes content and tokens through a localhost proxy instead of official provider endpoints, creating a meaningful trust and credential-forwarding risk. No clear malware or overt exfiltration is shown, but the proxy-mediated auth path and durable raw artifact storage make this higher risk than a direct API integration.
The code appears to be a legitimate local document-to-LLM fact extraction CLI, with no clear malware or sabotage behavior. The primary security concern is intentional outbound transmission of document contents and bearer credentials to a fully configurable endpoint, potentially over unencrypted HTTP. The hardcoded development token should be removed or made mandatory through secure configuration. The shown fragment is also syntactically incomplete, so execution cannot be fully verified from this input.