Back to plugin

Security audit

DebugBundle

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent DebugBundle integration, with disclosed credential use and optional management actions that users should allowlist carefully.

Install this only for agents that should access DebugBundle project data. Provide the narrowest useful token, review optional mutation tools before allowlisting them, and be especially cautious with project deletion, token creation or revocation, billing capacity changes, member management, GitHub, Slack, webhook, alert, probe, and analytics settings tools.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
dist/index.js:30702
Evidence
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:6590
Evidence
const llhttpWasmData = process.env.JEST_WORKER_ID ? require_llhttp_wasm() : void 0;

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/index.js:84670
Evidence
var BEARER = [REDACTED])\s+[A-Za-z0-9._~+\/-]{6,}/gi;

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
dist/index.js:83299
Evidence
rawAuthState = await readFile(authFilePath);