letta-configuration
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyscripts/setup_provider.py
LOWAnomalyLOW
scripts/setup_provider.py
The code is an overt provider-registration utility with no clear malware indicators, obfuscated payloads, persistence, or unauthorized system access. Its principal security risks are transmitting credentials to any user-selected server, using HTTP by default, and exposing secrets through command-line arguments. These risks warrant remediation in production use, especially by requiring HTTPS, validating or allowlisting the server, and accepting secrets through safer mechanisms. The exact fragment also contains an apparent syntax error at the end.
Confidence: 98%Severity: 62%
Audit Metadata