edge-candidate-agent
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/auto_detect_candidates.py
LOWAnomalyLOW
scripts/auto_detect_candidates.py
No explicit malicious payload, credential access, network exfiltration, or obfuscation is evident in this module. The primary security/supply-chain risk is the optional execution of an attacker-controlled external command via --llm-ideas-cmd (no timeout/allowlist/sandbox), followed by ingestion of untrusted YAML output that is propagated into exported ticket YAML artifacts and potentially downstream export/validation logic. If --llm-ideas-cmd can be influenced by an attacker (or shipped with unsafe defaults in automation), this becomes the dominant risk.
Confidence: 66%Severity: 55%
Audit Metadata