application-quality-assurance

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/with_server.py

The code is primarily a local orchestration utility that starts user-provided server commands, waits for localhost ports to be reachable, runs a user-provided command, and then terminates the servers. There is no clear evidence of malware functionality (no exfiltration/persistence/credential theft or obfuscation in this fragment). However, the use of subprocess.Popen(..., shell=True) with direct CLI-provided command strings and execution of a CLI-provided command makes the tool high-risk in environments where invocation arguments may be attacker-controlled (command injection/arbitrary code execution).

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Sep 23, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/qodex-ai%2Fai-agent-skills%2Fapplication-quality-assurance%2F@9ad779eb6803c58ac924c1a5333ddfda321500b9771b9b721612b1fe64441b11
Security Audit — socket — application-quality-assurance