compose-architecture
Audited by Socket on Oct 2, 2026
5 alerts found:
Anomalyx5The shown checker primarily performs read-only placeholder scanning and has no evident malware behavior. However, sourcing a project-controlled .composekit.conf executes arbitrary shell code, which is a significant risk when running the checker against an untrusted project. Treat the configuration as executable code or replace sourcing with safe data parsing.
The visible script is a repository convention checker and shows no direct malicious behavior. However, sourcing a configuration file from the project being scanned executes untrusted shell code and can enable arbitrary command execution. Run it only on trusted projects or replace executable configuration with a non-executable format.
The visible checker is ordinary validation logic and contains no apparent malware. However, sourcing .composekit.conf from the target project creates an arbitrary-code-execution risk when the project is untrusted. The helper is also executable shell code and must be trusted. Avoid running this script on untrusted project roots unless these sourced files are removed, validated, or otherwise trusted.
The checker’s visible scanning logic is straightforward and does not show malicious behavior. However, it executes `.composekit.conf` from the scanned project as shell code, creating a command-execution risk when used on an untrusted repository. Treat the config and sourced helper as executable code and review or avoid sourcing untrusted versions.
The script's stated purpose is a local source-code lint check and its own search/reporting logic shows no malicious behavior. Sourcing a project-controlled .composekit.conf creates an arbitrary-command-execution risk when run against an untrusted project. Treat that configuration as trusted code or replace sourcing with safe parsing.