matrix-communication
Audited by Socket on Sep 18, 2026
2 alerts found:
Anomalyx2The visible code is a Matrix messaging client and does not contain clear malware or unauthorized data exfiltration. It performs expected credential use and Matrix network operations. However, it weakens end-to-end encryption authentication by automatically trusting unverified devices and explicitly ignoring verification status. The local sys.path modification and opaque helper imports warrant review of adjacent files, especially _lib.py, but are not sufficient evidence of malicious behavior in this fragment.
The fragment is a readable Markdown and Matrix formatting utility with no evident malicious behavior or external side effects. Its main security concern is unsafe HTML generation: caller-controlled Markdown and link values are inserted into HTML without escaping or URL-scheme validation. This can cause HTML injection or XSS when the returned HTML is rendered in a browser or other HTML-capable client. The issue is contextual and is not evidence of supply-chain malware.