maintainx-debug-bundle
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyreferences/implementation-guide.md
LOWAnomalyLOW
references/implementation-guide.md
The fragment appears to be legitimate diagnostic and validation tooling, not malware. The main security risk is that verbose curl logging can save the MAINTAINX_API_KEY to maintainx-debug.log, and the support bundle copies recent logs without redaction despite advising users not to share API keys. Logs and support bundles should be sanitized before storage or sharing, and authorization headers should be suppressed or redacted.
Confidence: 96%Severity: 55%
Audit Metadata