kelly-devops
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
AnomalyAnomalyscripts/publish_airapp.mjs
LOWAnomalyLOW
scripts/publish_airapp.mjs
No clear evidence of malware, backdoor behavior, or obfuscated/hidden execution in this module. However, the script is high-impact from a supply-chain/policy perspective because it recursively reads nearly all files under a local content directory (only lightly excluded) and uploads their contents to a remote Busabase service via publishAirApp using env-provided credentials. If the directory contains sensitive data or unexpected artifacts, this can cause unintended data exposure.
Confidence: 62%Severity: 55%
Audit Metadata