mastra-smoke-test

Warn

Audited by Socket on Oct 1, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/discover-release-scope.sh

The script has a significant command-injection flaw in the unquoted heredoc. Attacker-controlled command-line values, or suitably crafted GitHub-derived values, can execute shell commands during report generation. Quote or escape interpolated values, or generate the document using a method that treats them strictly as data.

Confidence: 99%Severity: 72%
Audit Metadata
Analyzed At
Oct 1, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/mastra-ai%2Fmastra%2Fmastra-smoke-test%2F@165f231fde0ab9333652296bdb356199196eed58aba5e561d232d15b5d776681
Security Audit — socket — mastra-smoke-test