ast-grep
Audited by Socket on Feb 15, 2026
1 alert found:
Security[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN: The document is guidance for using ast-grep to construct and test AST-based searches. It presents workflows and examples without executing code, reading external inputs, or performing data exfiltration. The security posture remains low risk when treated as documentation and guidance; no malicious indicators detected. LLM verification: The fragment is benign documentation for ast-grep rule creation. It does not execute code, read credentials, or contact external services. The only notable anomalies are documentation formatting patterns involving backticks, which do not imply malicious behavior in this context.