formal-verify
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomalyscripts/verify-behavioral.py
LOWAnomalyLOW
scripts/verify-behavioral.py
No clear malicious payload or unauthorized data-theft behavior is present. The main risk is intentional dynamic execution of every Python specification file in a user-selected directory; untrusted specifications can execute arbitrary code, access local data, and affect the host process. The tool should only load trusted specification files, and traceback output should be considered potentially information-revealing.
Confidence: 98%Severity: 62%
Audit Metadata