woostack-respond
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
SecuritySecurityscripts/tests/fixtures/sensitive-input.json
MEDIUMSecurityMEDIUM
scripts/tests/fixtures/sensitive-input.json
No malicious runtime behavior or supply-chain compromise can be concluded from this fragment because it contains no executable code. However, the artifact embeds numerous high-sensitivity secrets (auth tokens, Basic auth material, session cookie, API key, password, database credentials) and even payment card data including CVV. This strongly suggests improper logging/redaction practices that create a major information-disclosure risk in telemetry/log pipelines.
Confidence: 72%Severity: 78%
Audit Metadata