task-monitor
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
SecuritySecuritytask_monitor/http_api.py
MEDIUMSecurityMEDIUM
task_monitor/http_api.py
The code implements a plausible task-monitoring API and does not show clear malware or obfuscation. However, it contains a high-impact command-execution sink: task.on_complete is executed with shell=True, and output_dir is interpolated without shell escaping. It also writes to a caller-influenced state_file path and exposes administrative operations without visible authentication. These issues could enable arbitrary command execution or filesystem writes if task registration is reachable by an untrusted user or if validation is incomplete. Review and constrain hook commands, avoid shell=True, validate paths against an allowed root, and enforce authentication and authorization.
Confidence: 94%Severity: 84%
Audit Metadata