cascading-fleet
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalylib/cascade-template.sh
LOWAnomalyLOW
lib/cascade-template.sh
This Bash module is not itself a payload with overt malicious code, but it is a high-impact supply-chain propagation tool. Its main security concerns are (1) executing an external Node/TypeScript CLI from a path derived from the PROJECTS environment variable and (2) bypassing git verification via --no-verify on both commits and pushes. If the wheelhouse CLI or the template input is compromised—or if PROJECTS is manipulated—this script could rapidly create and publish malicious changes across a fleet via direct pushes and/or automated PRs. No direct exfiltration/backdoor logic is visible in this fragment.
Confidence: 62%Severity: 64%
Audit Metadata