stitch
Audited by Socket on Sep 29, 2026
1 alert found:
SecurityNo explicit backdoor or classic malware behavior is evident in the shown fragment (no eval-style execution, reverse shells, or direct credential exfiltration code). However, the module’s primary security exposure is high-impact supply-chain execution: it installs an npm package at runtime based on user/environment-controlled parameters and then dynamically imports and executes code from the installed package. Separately, it downloads SDK-provided URLs to local files and may persist authentication fields into a local config file (secret-at-rest depends on whether upstream settings already blank credentials). Overall, treat this code as security-sensitive and require strict allowlisting/pinning of sdk-package/runtime-dir, integrity verification, URL/path validation, and guaranteed secret redaction before persistence.