channel-debug-core
Warn
Audited by Socket on Jun 29, 2026
1 alert found:
AnomalyAnomalyscripts/collect-channel-evidence.sh
LOWAnomalyLOW
scripts/collect-channel-evidence.sh
No direct evidence of classic malware behavior (no dynamic execution, no backdoor/persistence, no self-exfiltration beyond querying the configured service). However, the module performs privileged admin/log collection using an environment-provided bearer token, optionally sends a protection-bypass header, and writes sensitive admin responses (notably admin logs) to local disk. Treat as high-risk data-access code: security depends heavily on invocation context (trusted URL, controlled ADMIN/BYPASS values, and secure handling/storage of $OUT artifacts).
Confidence: 66%Severity: 68%
Audit Metadata