digdag

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
references/py-operator.md

No direct malicious behavior or data exfiltration is evident. The main security risk is the runtime os.system() pip-install pattern, which executes dependency installation code from requirements.txt on every run and can permit arbitrary code execution if dependencies or the requirements file are compromised. Use pinned and integrity-verified dependencies, avoid shell invocation where possible, and restrict container credentials and network access.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 23, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/treasure-data%2Ftd-skills%2Fdigdag%2F@a542601dc1aec29912c276f4acb0c47ffc259535ab44f705a5f3a67b06ce6950
Security Audit — socket — digdag