test-interactions
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalytest_interactions.py
LOWAnomalyLOW
test_interactions.py
The code is primarily a browser UI testing and visual-review CLI, and the supplied fragment contains no clear malware, persistence, destructive behavior, reverse shell, or broad system-data exfiltration. The main security concerns are the hardcoded bearer token, transmission of screenshots and test evidence to a local AI proxy, execution of delegated shell scripts, and possible JavaScript injection through the unvalidated scroll amount. Validate numeric manifest fields before interpolation, remove the embedded token in favor of secure configuration, constrain delegated scripts, and treat captured screenshots as sensitive data.
Confidence: 97%Severity: 58%
Audit Metadata