Reviewed deterministic Inspection · report 2

malek733/657

The pinned inspection emitted zero correlated findings while reporting one skipped file and one extraction error. Independent campaign reporting names malek733 and a malek733/657 payload URL, which makes the unresolved coverage gap material context but does not turn it into a machine-confirmed finding.

Exact snapshot
61ae8da0d391064372f5e6a450b9e49cc247c1613b2f929d0c67b4ff7a21e09b
Version / commit
5d313513ce14a9db9b20d73a862fd9038f8cfc04
Acquired
2026-09-25T11:38:38.288939+00:00
Reviewed
2026-09-25T11:45:00Z
Currentness
snapshot only
Machine report digest
b6e275343cf71b46fc3797ed4cf7a74b5d16e372c2504ccaba1d6ae68cb1359e

What was reviewed

  • Review every correlated deterministic finding in inspection run 8c0e6b71-74e9-4ff9-9a7a-c824d2b530e6 against the pinned snapshot; the correlated findings list is empty.
  • Preserve inspection coverage limitations, including the reported skipped file and extraction error, without converting uninspected material into an unsupported vulnerability finding.
  • Review independently sourced campaign context only as external context; do not treat external reporting as evidence that the pinned snapshot itself contains a machine-confirmed finding.

No deterministic finding was produced for the pinned snapshot, and the inspection remains coverage-limited because one file was skipped and one file had an extraction error. Independent reporting attributed to Venustech ADLab separately names malek733 among accounts associated with a GitHub-hosted malware-distribution campaign and lists malek733/657/128/01.txt as a next-stage payload URL. That external context increases the relevance of the unresolved coverage gap, but it does not convert the pinned inspection into a confirmed malware finding. The correct inspection result remains: zero correlated findings in the reviewed machine output, with unresolved coverage over the skipped or extraction-failed surface.

Inspection is deterministic machine work. This Audit is a reviewed editorial conclusion. Neither constitutes a blanket safe/unsafe certificate.

Exact disclosed material

Only the operator-cleared material below is included in this immutable public Release. External references are not additional reviewed snapshot files.

No source file is cleared for public disclosure. Private artifact bytes are not published automatically. Inspect the pinned evidence locators and scope below.

Deterministic inspection coverage

3 ordinary acquired files · 1 other inventory entries. Exact skip/extraction limits are described in the reviewed scope and limitations.

Pass means the rule condition was not found within its inspected scope, not that the target is safe.

iac

not applicable
2

mcp

not applicable
11

rag

skipped
1
not applicable
2

tls

not applicable
9

network

not applicable
2

secrets

skipped
13

web forms

not applicable
2

containers

not applicable
42

filesystem

not applicable
3

kubernetes

not applicable
49

randomness

not applicable
6

acquisition

pass
10

persistence

skipped
1
not applicable
2

web headers

not applicable
5

cryptography

not applicable
4

authorization

not applicable
18

code analysis

not applicable
1

shell process

not applicable
5

website trust

not applicable
5

authentication

not applicable
2

github actions

not applicable
7

remote loading

not applicable
3

deserialization

not applicable
8

dynamic context

skipped
2
not applicable
1

dynamic loading

not applicable
4

install scripts

not applicable
16

privacy logging

not applicable
3

download execute

skipped
1
not applicable
1

prompt injection

skipped
5

session handling

not applicable
3

agent permissions

skipped
1
not applicable
8

command injection

not applicable
6

dynamic execution

not applicable
4

web configuration

not applicable
1

environment access

not applicable
4

known dependencies

not applicable
1

network boundaries

not applicable
8

template execution

not applicable
3

cloud configuration

not applicable
124

hardcoded endpoints

not applicable
1

skills installation

skipped
1
not applicable
2

model output execution

not applicable
3
Machine coverage and toolchain identities
{
  "summary": {
    "groups": {
      "iac": {
        "not_applicable": 2
      },
      "mcp": {
        "not_applicable": 11
      },
      "rag": {
        "skipped": 1,
        "not_applicable": 2
      },
      "tls": {
        "not_applicable": 9
      },
      "network": {
        "not_applicable": 2
      },
      "secrets": {
        "skipped": 13
      },
      "web_forms": {
        "not_applicable": 2
      },
      "containers": {
        "not_applicable": 42
      },
      "filesystem": {
        "not_applicable": 3
      },
      "kubernetes": {
        "not_applicable": 49
      },
      "randomness": {
        "not_applicable": 6
      },
      "acquisition": {
        "pass": 10
      },
      "persistence": {
        "skipped": 1,
        "not_applicable": 2
      },
      "web_headers": {
        "not_applicable": 5
      },
      "cryptography": {
        "not_applicable": 4
      },
      "authorization": {
        "not_applicable": 18
      },
      "code_analysis": {
        "not_applicable": 1
      },
      "shell_process": {
        "not_applicable": 5
      },
      "website_trust": {
        "not_applicable": 5
      },
      "authentication": {
        "not_applicable": 2
      },
      "github_actions": {
        "not_applicable": 7
      },
      "remote_loading": {
        "not_applicable": 3
      },
      "deserialization": {
        "not_applicable": 8
      },
      "dynamic_context": {
        "skipped": 2,
        "not_applicable": 1
      },
      "dynamic_loading": {
        "not_applicable": 4
      },
      "install_scripts": {
        "not_applicable": 16
      },
      "privacy_logging": {
        "not_applicable": 3
      },
      "download_execute": {
        "skipped": 1,
        "not_applicable": 1
      },
      "prompt_injection": {
        "skipped": 5
      },
      "session_handling": {
        "not_applicable": 3
      },
      "agent_permissions": {
        "skipped": 1,
        "not_applicable": 8
      },
      "command_injection": {
        "not_applicable": 6
      },
      "dynamic_execution": {
        "not_applicable": 4
      },
      "web_configuration": {
        "not_applicable": 1
      },
      "environment_access": {
        "not_applicable": 4
      },
      "known_dependencies": {
        "not_applicable": 1
      },
      "network_boundaries": {
        "not_applicable": 8
      },
      "template_execution": {
        "not_applicable": 3
      },
      "cloud_configuration": {
        "not_applicable": 124
      },
      "hardcoded_endpoints": {
        "not_applicable": 1
      },
      "skills_installation": {
        "skipped": 1,
        "not_applicable": 2
      },
      "model_output_execution": {
        "not_applicable": 3
      }
    },
    "finding_count": 0,
    "checks_by_status": {
      "pass": 10,
      "skipped": 25,
      "not_applicable": 381
    },
    "skipped_surfaces": 1,
    "tool_error_count": 0,
    "findings_by_severity": {}
  },
  "coverage": {
    "cancelled": false,
    "fact_count": 2,
    "checks_expected": 416,
    "terminal_results": 416,
    "inventory_complete": true,
    "correlated_findings_omitted": 0,
    "files_with_extraction_errors": 1,
    "finding_review_complete_possible": true,
    "all_declared_checks_accounted_for": true
  },
  "toolchain": {
    "tools": [
      {
        "name": "gitleaks",
        "error": null,
        "status": "completed",
        "version": "8.30.1",
        "output_ref": "8d2879ce99c72c8a9519e7f52920a9e985a22ecb16dd270e581e713b79231833",
        "duration_ms": 2037,
        "ruleset_identity": "d37c74a9b3a03ea2ec975095da3efb4630f2d18bcc6d20632158bcf88162de6f"
      },
      {
        "name": "bandit",
        "error": null,
        "status": "not_applicable",
        "version": "1.8.6",
        "output_ref": null,
        "duration_ms": 0,
        "ruleset_identity": "not_applicable"
      },
      {
        "name": "osv-offline",
        "error": null,
        "status": "not_applicable",
        "version": "1",
        "output_ref": null,
        "duration_ms": 0,
        "ruleset_identity": "not_applicable"
      }
    ],
    "ruleset": {
      "by_group": {
        "iac": 2,
        "mcp": 11,
        "rag": 3,
        "tls": 9,
        "network": 2,
        "secrets": 12,
        "web_forms": 2,
        "containers": 42,
        "filesystem": 3,
        "kubernetes": 49,
        "randomness": 6,
        "acquisition": 10,
        "persistence": 3,
        "web_headers": 5,
        "cryptography": 4,
        "authorization": 18,
        "shell_process": 5,
        "website_trust": 5,
        "authentication": 2,
        "github_actions": 7,
        "remote_loading": 3,
        "deserialization": 8,
        "dynamic_context": 3,
        "dynamic_loading": 4,
        "install_scripts": 16,
        "privacy_logging": 3,
        "download_execute": 2,
        "prompt_injection": 5,
        "session_handling": 3,
        "agent_permissions": 9,
        "command_injection": 6,
        "dynamic_execution": 4,
        "web_configuration": 1,
        "environment_access": 4,
        "network_boundaries": 8,
        "template_execution": 3,
        "cloud_configuration": 124,
        "hardcoded_endpoints": 1,
        "skills_installation": 3,
        "model_output_execution": 3
      },
      "by_adapter": {
        "fact": 150,
        "document": 246,
        "workflow": 7,
        "inventory": 10
      },
      "enabled_checks": 413,
      "ruleset_sha256": "c467b3065b9578830aba8fbd8a0e7441e92d6e88732da4dfecf8383092e3d519",
      "disabled_checks": 0,
      "ruleset_version": "first-party/3",
      "candidate_checks": 101,
      "production_by_group": {
        "iac": 0,
        "mcp": 5,
        "rag": 0,
        "tls": 7,
        "network": 2,
        "secrets": 12,
        "web_forms": 0,
        "containers": 29,
        "filesystem": 3,
        "kubernetes": 48,
        "randomness": 5,
        "acquisition": 10,
        "persistence": 1,
        "web_headers": 0,
        "cryptography": 4,
        "authorization": 15,
        "shell_process": 4,
        "website_trust": 0,
        "authentication": 1,
        "github_actions": 7,
        "remote_loading": 0,
        "deserialization": 8,
        "dynamic_context": 0,
        "dynamic_loading": 4,
        "install_scripts": 6,
        "privacy_logging": 0,
        "download_execute": 1,
        "prompt_injection": 0,
        "session_handling": 0,
        "agent_permissions": 5,
        "command_injection": 5,
        "dynamic_execution": 2,
        "web_configuration": 0,
        "environment_access": 1,
        "network_boundaries": 8,
        "template_execution": 1,
        "cloud_configuration": 118,
        "hardcoded_endpoints": 0,
        "skills_installation": 0,
        "model_output_execution": 0
      },
      "production_by_adapter": {
        "fact": 61,
        "document": 234,
        "workflow": 7,
        "inventory": 10
      },
      "enabled_production_checks": 312
    },
    "python_version": "3.13.15",
    "inspector_version": "0.2.0",
    "toolchain_version": "sha256:0c8b220065b051d4047fb0a4ca8d7cbbc4d9d9441e0c3796c3f829c1aee3bbbd",
    "installed_identity": {
      "python": "3.13.15",
      "ruleset": {
        "by_group": {
          "iac": 2,
          "mcp": 11,
          "rag": 3,
          "tls": 9,
          "network": 2,
          "secrets": 12,
          "web_forms": 2,
          "containers": 42,
          "filesystem": 3,
          "kubernetes": 49,
          "randomness": 6,
          "acquisition": 10,
          "persistence": 3,
          "web_headers": 5,
          "cryptography": 4,
          "authorization": 18,
          "shell_process": 5,
          "website_trust": 5,
          "authentication": 2,
          "github_actions": 7,
          "remote_loading": 3,
          "deserialization": 8,
          "dynamic_context": 3,
          "dynamic_loading": 4,
          "install_scripts": 16,
          "privacy_logging": 3,
          "download_execute": 2,
          "prompt_injection": 5,
          "session_handling": 3,
          "agent_permissions": 9,
          "command_injection": 6,
          "dynamic_execution": 4,
          "web_configuration": 1,
          "environment_access": 4,
          "network_boundaries": 8,
          "template_execution": 3,
          "cloud_configuration": 124,
          "hardcoded_endpoints": 1,
          "skills_installation": 3,
          "model_output_execution": 3
        },
        "by_adapter": {
          "fact": 150,
          "document": 246,
          "workflow": 7,
          "inventory": 10
        },
        "enabled_checks": 413,
        "ruleset_sha256": "c467b3065b9578830aba8fbd8a0e7441e92d6e88732da4dfecf8383092e3d519",
        "disabled_checks": 0,
        "ruleset_version": "first-party/3",
        "candidate_checks": 101,
        "production_by_group": {
          "iac": 0,
          "mcp": 5,
          "rag": 0,
          "tls": 7,
          "network": 2,
          "secrets": 12,
          "web_forms": 0,
          "containers": 29,
          "filesystem": 3,
          "kubernetes": 48,
          "randomness": 5,
          "acquisition": 10,
          "persistence": 1,
          "web_headers": 0,
          "cryptography": 4,
          "authorization": 15,
          "shell_process": 4,
          "website_trust": 0,
          "authentication": 1,
          "github_actions": 7,
          "remote_loading": 0,
          "deserialization": 8,
          "dynamic_context": 0,
          "dynamic_loading": 4,
          "install_scripts": 6,
          "privacy_logging": 0,
          "download_execute": 1,
          "prompt_injection": 0,
          "session_handling": 0,
          "agent_permissions": 5,
          "command_injection": 5,
          "dynamic_execution": 2,
          "web_configuration": 0,
          "environment_access": 1,
          "network_boundaries": 8,
          "template_execution": 1,
          "cloud_configuration": 118,
          "hardcoded_endpoints": 0,
          "skills_installation": 0,
          "model_output_execution": 0
        },
        "production_by_adapter": {
          "fact": 61,
          "document": 234,
          "workflow": 7,
          "inventory": 10
        },
        "enabled_production_checks": 312
      },
      "contract": "inspector.toolchain/1",
      "platform": "x86_64",
      "executables": {
        "bandit": "60b67b200393962f5c59668119ab4433f7ef85fc78ede33b92bf8b7ce6c23cbe",
        "gitleaks": "88f91962aa2f93ac6ab281d553b9e125f5197bbbce38f9f2437f7299c32e5509"
      },
      "source_sha256": "498db5f132a7cfa3f70b9fc4c504ea0cb400c1c1a6dfc2ff1daaf2a45cb8a051",
      "toolchain_version": "sha256:0c8b220065b051d4047fb0a4ca8d7cbbc4d9d9441e0c3796c3f829c1aee3bbbd",
      "installed_packages": [
        [
          "PyYAML",
          "6.0.3"
        ],
        [
          "Pygments",
          "2.21.0"
        ],
        [
          "attrs",
          "26.1.0"
        ],
        [
          "bandit",
          "1.8.6"
        ],
        [
          "diggingbeagle-inspector",
          "0.2.0"
        ],
        [
          "iniconfig",
          "2.3.0"
        ],
        [
          "jsonschema",
          "4.26.0"
        ],
        [
          "jsonschema-specifications",
          "2025.9.1"
        ],
        [
          "markdown-it-py",
          "4.2.0"
        ],
        [
          "mdurl",
          "0.1.2"
        ],
        [
          "packaging",
          "25.0"
        ],
        [
          "pip",
          "26.2.1"
        ],
        [
          "pluggy",
          "1.6.0"
        ],
        [
          "psycopg",
          "3.2.6"
        ],
        [
          "psycopg-binary",
          "3.2.6"
        ],
        [
          "pytest",
          "9.0.2"
        ],
        [
          "referencing",
          "0.37.0"
        ],
        [
          "rich",
          "15.0.0"
        ],
        [
          "rpds-py",
          "2026.6.3"
        ],
        [
          "semver",
          "3.0.4"
        ],
        [
          "setuptools",
          "75.8.2"
        ],
        [
          "stevedore",
          "5.9.1"
        ]
      ],
      "tool_configurations": {
        "bandit.ini": "1ac8b7ca6758d27c826f2e2389d315d2449b636596ca15557871d9992e47bb04",
        "bandit.yaml": "0ee03e3824c3b4d993af538b46e200e66cd953af1c4063e25f1d7ad6cbc31f8a",
        "gitleaks.toml": "030234da2fd3a18911bc9d46cb682a4502ec50dee9de82f56a7a6d7ad7586135",
        "empty.gitleaksignore": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
      },
      "vulnerability_database_sha256": null
    },
    "vulnerability_db_version": "not_applicable"
  }
}

Reviewed findings

No material reviewed finding is asserted. Review scope and unresolved dispositions remain relevant.

Every deterministic finding reviewed

0 correlated machine findings have an explicit disposition.

Method

inspection-review/1. Target code was not executed.

Review the pinned deterministic inspection as untrusted evidence, assess all correlated findings, and preserve unresolved coverage without inventing vulnerabilities or external incident facts.

The correlated findings list contains zero items, so no finding disposition was fabricated. Machine coverage, tool status, skipped surface, and extraction-error limitations were reviewed and carried into the audit conclusion.

Not established / uninspected

  • The machine inspection emitted no correlated findings. Absence of findings is not evidence that the artifact is safe.
  • The snapshot reports one skipped file and inspection coverage reports one file with an extraction error; that surface was not fully evaluated by the deterministic finding pipeline.
  • No target code, package lifecycle hook, target test, binary, submodule, or browser JavaScript was executed.
  • Lexical rules do not prove dataflow, and Python call resolution is syntactic rather than a complete semantic resolution.
  • Dependency extraction is not a complete SBOM and known-vulnerability coverage was unavailable because no separately pinned offline vulnerability database ran.
  • Git history, submodule contents, and Git LFS objects were not acquired.
  • Independent reporting attributed to Venustech ADLab names malek733 and a malek733/657 payload URL in a wider campaign, but that reporting is external context rather than evidence produced by this pinned inspection and does not identify which pinned file had the extraction error.

Referenced Sources

Source links supply context or corroboration; they do not expand the immutable inspected snapshot.

Revision history

Revision 2 adds independently sourced campaign context at knowledge revision 45 while preserving the exact inspection identities, machine summary, zero-finding result, and coverage limitations. External reporting is explicitly separated from evidence produced by the pinned inspection.

    Cite this record

    DiggingBeagle. malek733/657. Audit 2; snapshot 61ae8da0d391064372f5e6a450b9e49cc247c1613b2f929d0c67b4ff7a21e09b. https://diggingbeagle.com/audits/malek733-657-890fb76c/

    Citation guidance

    Independent research

    The source stays with the story.

    Claims, evidence and corrections remain inspectable. About the project · Our methodology