sci-download

Warn

Audited by Socket on Aug 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
config.py

This code is primarily a local configuration/credential manager that reads and writes plaintext credentials/config files and derives WebVPN host/crypto parameters from local JSON. No direct malware behavior (e.g., network exfiltration, shell execution, or overt backdoors) is present in the shown fragment. The dominant security risk is the supply-chain/local-tampering exposure created by dynamically executing a sibling Python file (_shared/env_config.py) via exec_module(). Additional concerns are hardcoded WebVPN crypto defaults and persistent plaintext storage of API keys/tokens in a user-writable .env file.

Confidence: 60%Severity: 62%
AnomalyLOW
schools.json

This fragment is static JSON configuration with no executable logic, so it does not directly demonstrate malware behavior. However, it embeds repeated hardcoded symmetric crypto material (crypto_key and crypto_iv) using a single constant across multiple entries, including a static IV, which is a serious cryptographic/secret-handling design risk. Impact depends entirely on how downstream code consumes these fields; nevertheless, the embedded secrets and lack of cryptographic context warrant urgent review/rotation and verification of the consuming crypto implementation.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Aug 16, 2026, 11:24 AM
Package URL
pkg:socket/skills-sh/shzhao27208%2Faut_sci_write%2Fsci-download%2F@5c12fd5b35a89a4389aeb6250f648b60439227859683cb675998e04a244b324e
Security Audit — socket — sci-download