T09 · Insecure Skill Coding Practices
- Location
evolve.js:585- Finding
Automatic Execution of Untrusted Project Scripts During Health Checks
- Content
View full analysis
0) { health.errors.push({ type: 'test_failure', message: `Tests failed: ${health.testResults.failed} failures` }); } } } else { health.testResults = { passed: 0, failed: 0, total: 0, skipped: true }; } // 3. Lint check (if exists) if (pkg.scripts && pkg.scripts.lint) { try { execFileSync('npm', ['run', 'lint'], { cwd: this.projectPath, encoding: 'utf-8', timeout: 30000, stdio: ['pipe', 'pipe', 'pipe'] }); } catch (e) { const output = (e.stderr || e.stdout || e.message || ...[truncated 3085 chars]- Remediation
View remediation
