jev-capability-advisor
Warn
Audited by Socket on Sep 30, 2026
1 alert found:
AnomalyAnomalyscripts/decision_cache.py
LOWAnomalyLOW
scripts/decision_cache.py
The code is a cache implementation, not apparent malware. However, unvalidated `key` values are used in filesystem paths; traversal components may permit reads or replacement writes outside the cache directory when the process has suitable permissions. Validate keys against the intended filename format before path construction.
Confidence: 97%Severity: 58%
Audit Metadata