implementing-search-filter
Fail
Audited by Socket on Feb 15, 2026
1 alert found:
Obfuscated FileObfuscated Filescripts/generate_filter_query.py
HIGHObfuscated FileHIGH
scripts/generate_filter_query.py
The module is not actively malicious but contains serious security issues and a functional bug. Primary risk: unsanitized interpolation of untrusted input into SQL query strings (SQL injection) and unvalidated insertion of user input into Elasticsearch DSL (query manipulation / resource abuse). Additionally, _add_text_search contains a syntax error that prevents execution of that branch. Fix by using parameterized queries, input validation/escaping, and repairing the broken assignment. Do not execute printed SQL without sanitization.
Confidence: 98%
Audit Metadata