view-your-harness
Warn
Audited by Socket on Aug 17, 2026
1 alert found:
AnomalyAnomalyscripts/serve.py
LOWAnomalyLOW
scripts/serve.py
No direct signs of malicious payloads (e.g., remote C2, credential theft, persistence) are present in this fragment. However, it implements unauthenticated localhost HTTP APIs that can read and return local file contents/images from an allowlisted directory set and can trigger OS open/reveal actions based on network input. If an attacker can reach the listening port or influence requests, the primary risks are local privacy breach/exfiltration and process-intent execution. Supply-chain risk is also partially dependent on the behavior/integrity of the separately executed index.py.
Confidence: 68%Severity: 61%
Audit Metadata