mastra-smoke-test
Warn
Audited by Socket on Oct 1, 2026
1 alert found:
SecuritySecurityscripts/discover-release-scope.sh
MEDIUMSecurityMEDIUM
scripts/discover-release-scope.sh
The script has a significant command-injection flaw in the unquoted heredoc. Attacker-controlled command-line values, or suitably crafted GitHub-derived values, can execute shell commands during report generation. Quote or escape interpolated values, or generate the document using a method that treats them strictly as data.
Confidence: 99%Severity: 72%
Audit Metadata