sci-download
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalyschools.json
LOWAnomalyLOW
schools.json
This module is static configuration only, with no direct malware or runtime exploitation behavior visible. The main supply-chain security concern is the embedded, plaintext, constant cryptographic material (crypto_key/crypto_iv) reused across multiple entries. If the consuming application uses these values for encryption/decryption or session protection, this represents a material confidentiality/integrity risk. Verify in the consumer how these fields are used and remove/replace hardcoded secrets with secure key management (per-install/per-session keys, proper IV handling, and secrets delivered via protected channels).
Confidence: 100%Severity: 60%
Audit Metadata