elasticsearch-file-ingest

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/ingest.js

No strong evidence of embedded malware, credential theft, or covert exfiltration in this file itself. The primary security concern is the high-impact design feature that executes a user-specified JavaScript module via import()/require() when --transform is used, which can lead to arbitrary code execution if the CLI argument or transform source is untrusted. Treat this CLI as unsafe in multi-tenant or untrusted-invocation scenarios unless --transform is tightly controlled.

Confidence: 75%Severity: 55%
Audit Metadata
Analyzed At
Jun 28, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/kilo-org%2Fkilo-marketplace%2Felasticsearch-file-ingest%2F@925d2e0370b2e020da1b79ab34eb73aa26c5b13721c4fbd04db44a015fbb9fd2
Security Audit — socket — elasticsearch-file-ingest