configuration-properties
Warn
Audited by Socket on Sep 9, 2026
1 alert found:
AnomalyAnomalyexamples/bad-client.java
LOWAnomalyLOW
examples/bad-client.java
No evidence of intentional malware or malicious supply-chain behavior exists in this fragment. It contains configuration security and reliability issues: a misspelled timeout key, ambiguous string typing, and a predictable default token. The default token should be removed or restricted to non-production profiles, and configuration should be strongly typed and validated.
Confidence: 98%Severity: 55%
Audit Metadata