flask-app-builder
Warn
Audited by Socket on Jun 23, 2026
2 alerts found:
SecurityAnomalySecurityreferences/app-registry.md
MEDIUMSecurityMEDIUM
references/app-registry.md
Anomalyreferences/feature-patterns.md
LOWAnomalyLOW
references/feature-patterns.md
No strong, direct malware indicators (no eval/Function/command execution/backdoor persistence observed). The main supply-chain/security concerns are (1) sensitive credential-dependent external calls: runtime key retrieval from a third-party endpoint and (2) forwarding of arbitrary task_text to an external bridge service using a server secret token, which could enable data exfiltration depending on how task_text is sourced. Additional issues include leaking raw exception messages to clients and disclosing saved upload paths. Recommend auditing call sites for get_api_key_from_kys() and post_to_ecdash(), enforcing content/size limits on uploads, and suppressing detailed exception strings.
Confidence: 62%Severity: 60%
Audit Metadata