panic-attack estate sweep — Track C tracking issue
panic-attack assail flagged the findings below in this repo on 2026-05-26. They are aggregated here for human triage rather than as individual PRs because each requires judgement (supply-chain pin choice, schema-design call, mutation-test gap, etc.).
PA001/PA007 UnsafeCode/UnsafeFFI findings are NOT in this list. Findings already suppressed in audits/assail-classifications.a2ml are also excluded.
Estate tracker: hyperpolymath/panic-attack#32.
CommandInjection (3 findings)
file:line list
Critical tests/ai-isolation/network-tests/container_escape_test.sh:? eval usage in tests/ai-isolation/network-tests/container_escape_test.sh
Critical scripts/install/install.sh:? eval usage in scripts/install/install.sh
### `DynamicCodeExecution` (1 findings)
file:line list
### `HardcodedSecret` (7 findings)
file:line list
Critical monitoring/scripts/backup_dashboards.sh:? Possible hardcoded secret in monitoring/scripts/backup_dashboards.sh
Critical scripts/management/uninstall.sh:? Possible hardcoded secret in scripts/management/uninstall.sh
Critical scripts/management/backup.sh:? Possible hardcoded secret in scripts/management/backup.sh
Critical scripts/management/init-database.sh:? Possible hardcoded secret in scripts/management/init-database.sh
Critical scripts/management/update.sh:? Possible hardcoded secret in scripts/management/update.sh
Critical scripts/management/health-check.sh:? Possible hardcoded secret in scripts/management/health-check.sh
### `SupplyChain` (1 findings)
file:line list
### `UnboundedAllocation` (3 findings)
file:line list
Critical cli/src/commands/sync.rs:? Potential unbounded allocation pattern detected in cli/src/commands/sync.rs
Critical cli/src/config.rs:? Potential unbounded allocation pattern detected in cli/src/config.rs
🤖 Discovered during the panic-attack estate sweep (2026-05-26). See hyperpolymath/panic-attack#32 for campaign tracker.
panic-attack estate sweep — Track C tracking issue
panic-attack assailflagged the findings below in this repo on 2026-05-26. They are aggregated here for human triage rather than as individual PRs because each requires judgement (supply-chain pin choice, schema-design call, mutation-test gap, etc.).PA001/PA007 UnsafeCode/UnsafeFFI findings are NOT in this list. Findings already suppressed in
audits/assail-classifications.a2mlare also excluded.Estate tracker: hyperpolymath/panic-attack#32.
CommandInjection(3 findings)file:line list
file:line list
file:line list
file:line list
file:line list
🤖 Discovered during the panic-attack estate sweep (2026-05-26). See hyperpolymath/panic-attack#32 for campaign tracker.