embedding-ft
Warn
Audited by Socket on Feb 16, 2026
1 alert found:
AnomalyAnomalyreferences/job-contract.md
LOWAnomalyLOW
references/job-contract.md
The workflow presents a pragmatic, low-retry design emphasizing determinism and safety but introduces a notable dynamic invocation risk through contentFunction supplied by the payload. Without strict whitelisting and sandboxing of contentFunction, there is a medium-to-high risk of code execution or unintended side effects. Atomicity concerns and shutdown-race handling also warrant explicit transactional boundaries and better visibility. Overall, the design is not malicious but requires stronger input validation, function governance, and robust observability to mitigate data integrity and security risks.
Confidence: 65%Severity: 60%
Audit Metadata