data-analysis

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/analyze.py

The fragment appears intended as a local data-analysis CLI, not as deliberate malware. No direct evidence of credential theft, persistence, destructive behavior, or network exfiltration is present. However, automatic pip installation and DuckDB extension installation introduce supply-chain and network risks, while direct SQL execution and unescaped file/sheet interpolation create security risks when inputs are untrusted. The provided code is incomplete or syntactically corrupted, so behavior of omitted functions cannot be assessed.

Confidence: 94%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:01 PM
Package URL
pkg:socket/skills-sh/bytedance%2Fdeer-flow%2Fdata-analysis%2F@f34dc535ef091307f9a7be6b6d02462e223a59a996fe8a3c3a6e37f57dd6e862
Security Audit — socket — data-analysis