ai-observability-promptfoo
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalyexamples/custom-providers.md
LOWAnomalyLOW
examples/custom-providers.md
The fragment contains legitimate LLM evaluation documentation and CI/CD examples. It does not demonstrate malware or intentional data theft. The primary supply-chain risk is executing npx promptfoo@latest without pinning or integrity verification. Additional security risks include possible exposure of prompts and results through --share, artifacts, and caches, and potential secret misuse when evaluating pull-request-controlled content. Pin the package version, restrict workflows for untrusted forks, minimize permissions, avoid sharing sensitive results, and isolate or validate caches.
Confidence: 93%Severity: 61%
Audit Metadata