ae-data-integration-helper

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
references/logbus2_parser_plugin.md

No explicit malware logic (e.g., credential theft, reverse shell, or suspicious network destinations) is shown in the provided excerpts. However, the Logbus2 configuration indicates runtime execution of an external jar via parser.cmd with depend_sh=true, which creates a high-impact supply-chain/RCE surface if the referenced jar or configuration can be tampered with. Additionally, the Java snippet logs response content and stack traces (data exposure risk), and the gRPC client uses insecure transport. Treat as an elevated security risk pending review of the actual server-side gRPC handling and the executed parser jar/plugin behavior.

Confidence: 45%Severity: 62%
Audit Metadata
Analyzed At
Aug 21, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/thinkingaiagenticengine%2Fae-cli%2Fae-data-integration-helper%2F@0f53617caf32e1593515e3e1e2cba2722e50b8820bcb7bc4a249aef9fcd6d00f
Security Audit — socket — ae-data-integration-helper