jeecg-codegen
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalydocs/skill-usage-guide.md
LOWAnomalyLOW
docs/skill-usage-guide.md
The fragment contains no direct malware or executable malicious payload. It documents a powerful code-generation workflow with filesystem and database modification capabilities. The hardcoded `root`/`root` database credential is a significant security issue, and automatic authorization of generated menus to the admin role warrants review. The actual implementation should be audited for command execution, path validation, secret handling, confirmation enforcement, and privilege boundaries.
Confidence: 98%Severity: 63%
Audit Metadata