add-dashboard
Warn
Audited by Socket on Aug 30, 2026
1 alert found:
SecuritySecurityresources/dashboard-pusher.ts
MEDIUMSecurityMEDIUM
resources/dashboard-pusher.ts
No clear signs of overt malware behavior (e.g., command execution, remote payload loading, or non-local network targeting) are present in this module. However, it is explicitly designed to collect broad, potentially sensitive internal data—including recent inbound/outbound message records and log excerpts—and repeatedly send it over HTTP to a local dashboard service authenticated with a bearer secret. This is a significant confidentiality/privacy risk if the receiver is untrusted, compromised, or can be spoofed locally, and error suppression reduces observability of the data-export behavior.
Confidence: 66%Severity: 78%
Audit Metadata