Public artifact · version-bound review
Sompote/Tiger_bot
Analyst conclusion
The pinned Tiger_bot snapshot contains thirty deterministic review candidates, but the available evidence supports a review map rather than a vulnerability verdict. The strongest concentration is around credential handling and logging, followed by subprocess and code-analysis surfaces, with additional candidates for randomness, install-time execution, environment access, and npm package configuration. Those observations are useful because they identify where a human reviewer should look first; they are not sufficient by themselves to show credential theft, command injection, malicious installation behavior, or another exploit path. The Inspector accounted for every declared check, yet known-vulnerability analysis failed and some surfaces or snapshot entries were skipped or redacted. Because the source excerpts and surrounding data flow needed to adjudicate the candidates are not available in the embedded context, this exact reviewed version remains unrated. That status means the evidence is insufficient for a defensible safety rating; it is not a claim that the project is safe, unsafe, benign, or malicious.
Reviewed sourceSompote/Tiger_bot·370409497ac11e8fc5dde5e4667068ed0aacf0ae
Why
Read the material findings and stated coverage limits below.
Potential harm
The safety impact is not established because required review work remains incomplete.
Before you use it
Do not treat this report as a safety decision. Resolve the stated review gap before relying on the artifact.
Analysis: facts, inference and conditions
Observed: No material finding was recorded in the stated scope.
Interpretation: This does not establish safety outside that scope.
Conditional outcome: Changes to the artifact, configuration, dependencies or deployment can change the result.
What to do next
Do not treat this report as a safety decision. Resolve the stated review gap before relying on the artifact.
What held up in scope
184 deterministic checks completed without the checked condition being observed. These are scoped negative observations, not proof of safety.
Reviewed scope
- This report covers only Sompote/Tiger_bot at commit 370409497ac11e8fc5dde5e4667068ed0aacf0ae, acquired as immutable snapshot 92006138-0a9b-4f5b-b4ff-d21c7dbf4656 with SHA-256 2afafb3d7508fb8a56428cbdb418b539ca11bfd47b8f5fe3e62832d628b483dd.
- The Inspector accounted for all 416 declared checks. The result set contains 184 pass results, 8 finding-status checks, 1 skipped result, 222 not-applicable results, and 1 error. These statuses describe deterministic checks, not a whole-artifact security verdict.
- The 30 deterministic candidates are concentrated in a small number of review themes: credential transport and logging, subprocess and code-execution surfaces, randomness, install-time behavior, environment access, and package publication/configuration.
- All 30 pinned machine finding identities remain represented exactly once through the existing finding assessments. This compose pass does not silently promote, dismiss, merge, or replace them.
- The acquired snapshot contains 109 included files, 45 skipped entries, and 2 redactions. Conclusions do not extend to omitted material, Git history, submodules, Git LFS objects, or later upstream versions.
- No target code, package lifecycle hook, test, binary, submodule, browser JavaScript, generated payload, or downloaded artifact was executed.
This conclusion is limited to the reviewed version and purpose. It is not a universal certification.
What remains unknown
- The embedded research context contains machine finding IDs, check IDs, file hashes, and exact locations, but report_context.findings is empty and the relevant source excerpts are not embedded.
- Credential-in-URL, credential-in-arguments, token-logging, and environment-access candidates cannot establish that a live secret is present or exposed without the underlying value and data-flow context.
- Subprocess and code-analysis candidates do not establish command injection, privilege escalation, or unsafe execution without command construction, caller trust, argument provenance, PATH control, and privilege context.
- The Math.random candidate is not a security defect by itself; impact depends on whether the generated value participates in authentication, authorization, secrecy, uniqueness, or another security-sensitive function.
- The npm postinstall candidate establishes an install-time execution surface but not the behavior or risk of the invoked lifecycle command because its implementation is not present in the embedded context.
- Public npm publication configuration describes package distribution behavior and is not itself a vulnerability.
- Pass results apply only to their named deterministic conditions and inspected scope; they are not evidence that the surrounding code or artifact is safe.
- Known-vulnerability coverage is unavailable because the pinned osv-offline adapter failed and no vulnerability database version is available.
- The machine summary reports three skipped surfaces and one skipped check result. The snapshot also records 45 skipped entries and two redactions; those omissions are not assumed safe or irrelevant.
- Git history, submodule contents, and Git LFS objects were not acquired, and no runtime behavior was exercised.
- Because exact source excerpts are unavailable in this fallback context, the 30 deterministic candidates remain evidence leads rather than fully adjudicated editorial findings.
- A safety rating cannot be defended from the available evidence. The 30 machine candidates are located and categorized, but exact source context is missing, the offline vulnerability adapter failed, and skipped or reduced surfaces remain unresolved.
Report history
Compose pass for report revision 3. Reworked the existing enriched Audit into a standalone reader-facing dossier with a clearer review boundary, candidate-family interpretation, methodology, limitations, and conclusion. Machine-owned Inspection identity and prior finding dispositions remain unchanged.
Technical review details
Inspection coverage
109 ordinary acquired files were included; 45 inventory entries were skipped. A passed check means only that its condition was not found in its inspected scope.
30 machine observations received analyst dispositions: 30 unresolved.
Method
inspection-review/1. Target code was not executed.
Convert the existing inspection-bound research into a concise technical dossier without changing machine-owned identity, manufacturing evidence, or treating scanner output as a verdict.
The compose pass preserves the existing evidence-bound dispositions and focuses the reader on what the detector families imply, what they do not establish, and which unresolved evidence gaps prevent a rating. No analyst-only finding is added because no new exact source range was registered through the private Inspection source interface.
416 across 42 check groups
Check matches are not confirmed vulnerabilities. Not applicable and skipped are kept separate.
AI & agent boundaries
27 no match · 7 not applicable
6 check groups
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| agent permissions | 0 | 0 | 0 | 9 | 0 |
| dynamic context | 0 | 0 | 0 | 3 | 0 |
| mcp | 0 | 0 | 0 | 4 | 7 |
| model output execution | 0 | 0 | 0 | 3 | 0 |
| prompt injection | 0 | 0 | 0 | 5 | 0 |
| rag | 0 | 0 | 0 | 3 | 0 |
Code & supply chain
3 matched · 1 errors · 52 no match · 7 not applicable
13 check groups
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| code analysis | 1 | 0 | 0 | 0 | 0 |
| command injection | 0 | 0 | 0 | 6 | 0 |
| deserialization | 0 | 0 | 0 | 8 | 0 |
| download execute | 0 | 0 | 0 | 2 | 0 |
| dynamic execution | 0 | 0 | 0 | 4 | 0 |
| dynamic loading | 0 | 0 | 0 | 4 | 0 |
| github actions | 0 | 0 | 0 | 0 | 7 |
| install scripts | 2 | 0 | 0 | 14 | 0 |
| known dependencies | 0 | 1 | 0 | 0 | 0 |
| remote loading | 0 | 0 | 0 | 3 | 0 |
| shell process | 0 | 0 | 0 | 5 | 0 |
| skills installation | 0 | 0 | 0 | 3 | 0 |
| template execution | 0 | 0 | 0 | 3 | 0 |
Identity & sensitive data
5 matched · 1 skipped · 38 no match · 15 not applicable
10 check groups
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| authentication | 0 | 0 | 0 | 2 | 0 |
| authorization | 0 | 0 | 0 | 3 | 15 |
| cryptography | 0 | 0 | 0 | 4 | 0 |
| environment access | 2 | 0 | 0 | 2 | 0 |
| filesystem | 0 | 0 | 0 | 3 | 0 |
| persistence | 0 | 0 | 0 | 3 | 0 |
| privacy logging | 1 | 0 | 0 | 2 | 0 |
| randomness | 1 | 0 | 0 | 5 | 0 |
| secrets | 1 | 0 | 1 | 11 | 0 |
| session handling | 0 | 0 | 0 | 3 | 0 |
Network & web
13 no match · 20 not applicable
8 check groups
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| hardcoded endpoints | 0 | 0 | 0 | 1 | 0 |
| network | 0 | 0 | 0 | 2 | 0 |
| network boundaries | 0 | 0 | 0 | 0 | 8 |
| tls | 0 | 0 | 0 | 9 | 0 |
| web configuration | 0 | 0 | 0 | 1 | 0 |
| web forms | 0 | 0 | 0 | 0 | 2 |
| web headers | 0 | 0 | 0 | 0 | 5 |
| website trust | 0 | 0 | 0 | 0 | 5 |
Infrastructure
44 no match · 173 not applicable
4 check groups
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| cloud configuration | 0 | 0 | 0 | 0 | 124 |
| containers | 0 | 0 | 0 | 42 | 0 |
| iac | 0 | 0 | 0 | 2 | 0 |
| kubernetes | 0 | 0 | 0 | 0 | 49 |
Acquisition & other checks
10 no match
1 check group
| Group | Matched | Errors | Skipped | No match | Not applicable |
|---|---|---|---|---|---|
| acquisition | 0 | 0 | 0 | 10 | 0 |
Totals remain for the whole inspection. Filters affect the group details only.
No groups match these filters.
Cite this record
DiggingBeagle. Sompote/Tiger_bot. Published Audit revision 3; reviewed artifact SHA-256 2afafb3d7508fb8a56428cbdb418b539ca11bfd47b8f5fe3e62832d628b483dd. https://diggingbeagle.com/audits/sompote-tiger-bot-b2961480/
Citation guidance