ingest-code
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalyingest_code.py
LOWAnomalyLOW
ingest_code.py
No clear, intentional malware (reverse shell, cryptominer, hardcoded malicious domain) was found in this file. However, the code performs large-scale reading of repository files and will send extracted text and CWE findings to a configurable memory service (HTTP POST) or execute local 'memory' scripts. This design creates a realistic supply-chain/data-exfiltration risk if MEMORY_SERVICE_URL or local skill scripts are attacker-controlled. The auto-pip install on import and dynamic imports from home directories are additional risky behaviors. Use only with trusted memory backends and trusted local skill modules.
Confidence: 90%Severity: 60%
Audit Metadata