jeecg-codegen

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
docs/skill-usage-guide.md

The fragment contains no direct malware or executable malicious payload. It documents a powerful code-generation workflow with filesystem and database modification capabilities. The hardcoded `root`/`root` database credential is a significant security issue, and automatic authorization of generated menus to the admin role warrants review. The actual implementation should be audited for command execution, path validation, secret handling, confirmation enforcement, and privilege boundaries.

Confidence: 98%Severity: 63%
Audit Metadata
Analyzed At
Sep 19, 2026, 12:25 PM
Package URL
pkg:socket/skills-sh/jeecgboot%2Fskills%2Fjeecg-codegen%2F@b234472be11f564d9da6e825cfce9681e60ffc1f349c43c7d355eff8deddef39
Security Audit — socket — jeecg-codegen