spot-companies-hiring-to-solve-specific-problems

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Anomaly
AnomalyLOW
api.sh

No clear malware behavior is evident in this fragment (single fixed HTTPS destination, no persistence/backdoor/exfil beyond intended API authentication). The primary security risk is the use of `source` on a discovered `.env` file discovered via directory traversal, which can enable arbitrary command execution if the `.env` contents/location are attacker-controlled. METHOD/ENDPOINT are unvalidated and could cause unintended requests, but they do not appear to enable arbitrary host targeting in this snippet.

Confidence: 68%Severity: 56%
Audit Metadata
Analyzed At
Apr 18, 2026, 06:52 PM
Package URL
pkg:socket/skills-sh/openfunnel%2Fopenfunnel-skills%2Fspot-companies-hiring-to-solve-specific-problems%2F@dc71624dde6e1de7f8751f7b218c6733d1ee846c