dx-harness
Audited by Socket on Sep 16, 2026
5 alerts found:
Anomalyx5The fragment is a repository verification harness, not apparent malware. It deliberately executes bootstrap, reset, and test commands, and its use of eval creates a command-injection risk if the fingerprint or discovered command fields are untrusted or attacker-controlled. Execution occurs in a temporary worktree but still uses the invoking user's privileges and may access the host environment. No credential theft, exfiltration, persistence, obfuscation, or destructive behavior is evident in this file.
The script is a benchmarking utility that creates a fresh worktree, runs a configured bootstrap command and a recognized test command, measures their durations, and emits JSON. There is no clear evidence of embedded malware, credential theft, persistence, exfiltration, or system damage in the shown code. The primary security issue is command injection: `.bootstrap_command` is treated as shell code and executed via `eval`, so an attacker controlling the fingerprint JSON or discovery output can run arbitrary commands. This may be acceptable only when the fingerprint and repository are fully trusted; otherwise the bootstrap command should be validated or executed without eval, with an explicit allowlist and safer argument handling.
The visible script appears to be a development database seeding template with a production guard and a bounded database connectivity wait. The primary security concern is that SEED_BODY is executed as raw shell code after substitution, making the generator or template inputs a high-impact code-injection boundary. Test credentials are also intentionally exposed in output. No direct malicious payload is present in the supplied fragment, but the omitted seed body must be reviewed before trusting the generated script.
This is a destructive development-environment reset script rather than clear malware. The primary security concern is that generated placeholders and bootstrap.sh execute with full shell privileges, so a compromised generator or local bootstrap script could cause arbitrary actions. The .env backup may retain sensitive credentials, and the production protection is limited. Review the rendered commands and bootstrap.sh before execution.
The visible script is a conventional repository bootstrap script with no clear evidence of malware or intentional data theft. Its security depends heavily on the substituted command values and the executable migration/seed scripts, which can run arbitrary commands from the checkout. Review the rendered placeholders and invoked scripts before execution, especially when obtaining the repository from an untrusted source.