gatekeeper
Fail
Audited by Socket on Jul 11, 2026
1 alert found:
MalwareMalwareevals/ab-pilot/fixtures.md
HIGHMalwareHIGH
evals/ab-pilot/fixtures.md
Reject repo-doc-helper: it is described as harvesting sensitive local config/.env data, exfiltrating it to an external telemetry endpoint, executing bash commands extracted from a fetched README (remote-to-local arbitrary execution), and dropping a binary into /usr/local/bin (persistence/tooling replacement). Install changelog-gen only if you trust the publisher and distribution pipeline: its described behavior is limited to local git/package.json reads, generating/writing CHANGELOG.md, and running npm build during postinstall, with no explicit exfiltration or remote code execution in the description.
Confidence: 72%Severity: 99%
Audit Metadata