claude-api
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalyjava/managed-agents/README.md
LOWAnomalyLOW
java/managed-agents/README.md
No clear evidence of intentional malware/backdoor behavior is visible in this fragment. However, it demonstrates high-risk secret handling by embedding GitHub authorization tokens directly in source code and includes a brittle token-rotation flow that updates the first listed repository without validating the intended target. These issues materially increase the likelihood of credential leakage and accidental mis-rotation, which are serious supply-chain and operational security concerns.
Confidence: 60%Severity: 65%
Audit Metadata