kelly-education-intel
Warn
Audited by Socket on Aug 25, 2026
1 alert found:
AnomalyAnomalyscripts/publish_airapp.mjs
LOWAnomalyLOW
scripts/publish_airapp.mjs
The module appears to be a legitimate publishing/deployment automation tool, but it carries a significant supply-chain security risk due to its broad recursive packaging and uploading of almost all files under appRoot to an external Busabase service using high-privilege API credentials. There are no strong indicators of intentional malware/backdoors in the code shown; the primary concern is accidental sensitive-data exfiltration via overly permissive file inclusion and lack of allowlisting/content filtering.
Confidence: 70%Severity: 55%
Audit Metadata