simready-foundation-create-package
Warn
Audited by Socket on Oct 3, 2026
1 alert found:
SecuritySecurityassets/scripts/sr_pkg_sample/_conformance_writer.py
MEDIUMSecurityMEDIUM
assets/scripts/sr_pkg_sample/_conformance_writer.py
The fragment has a significant code-execution risk: `eval` is used on feature-summary strings. This is unsafe when summaries are untrusted. The code does not otherwise show clear malicious behavior; replace `eval` with safe parsing such as `json.loads` where the inputs are JSON.
Confidence: 99%Severity: 78%
Audit Metadata