flutter-device-testing

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_lifecycle_matrix.py

The code is a transparent mobile lifecycle test runner. It does not show evidence of embedded malware or covert data theft. Its principal security consideration is intentional arbitrary subprocess execution from user-controlled matrix step arguments when --execute is used, plus potentially sensitive URI or command output exposure. Only trusted matrix files should be executed, and report paths and redaction behavior should be reviewed. If the displayed indentation is exact, the file also requires a class body such as pass to import successfully.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 15, 2026, 01:49 PM
Package URL
pkg:socket/skills-sh/thiennc-tesoglobal%2Fflutter-skills%2Fflutter-device-testing%2F@0b4c22bf05b12d3e489452e952fbd85433c4d15426a04fb26ab21044a77e719b
Security Audit — socket — flutter-device-testing