Public artifact · version-bound review

Sompote/Tiger_bot

UnratedCoverage incomplete
Public artifactReview 3
Assessment Not rated Coverage incomplete
Primary finding No material finding recorded
Severity Not assigned
Confidence Not assigned
Findings 0 reviewed · 0 unresolved

Analyst conclusion

The pinned Tiger_bot snapshot contains thirty deterministic review candidates, but the available evidence supports a review map rather than a vulnerability verdict. The strongest concentration is around credential handling and logging, followed by subprocess and code-analysis surfaces, with additional candidates for randomness, install-time execution, environment access, and npm package configuration. Those observations are useful because they identify where a human reviewer should look first; they are not sufficient by themselves to show credential theft, command injection, malicious installation behavior, or another exploit path. The Inspector accounted for every declared check, yet known-vulnerability analysis failed and some surfaces or snapshot entries were skipped or redacted. Because the source excerpts and surrounding data flow needed to adjudicate the candidates are not available in the embedded context, this exact reviewed version remains unrated. That status means the evidence is insufficient for a defensible safety rating; it is not a claim that the project is safe, unsafe, benign, or malicious.

Reviewed sourceSompote/Tiger_bot·370409497ac11e8fc5dde5e4667068ed0aacf0ae

Why

Read the material findings and stated coverage limits below.

Potential harm

The safety impact is not established because required review work remains incomplete.

Before you use it

Do not treat this report as a safety decision. Resolve the stated review gap before relying on the artifact.

Analysis: facts, inference and conditions

Observed: No material finding was recorded in the stated scope.

Interpretation: This does not establish safety outside that scope.

Conditional outcome: Changes to the artifact, configuration, dependencies or deployment can change the result.

What to do next

Do not treat this report as a safety decision. Resolve the stated review gap before relying on the artifact.

What held up in scope

184 deterministic checks completed without the checked condition being observed. These are scoped negative observations, not proof of safety.

Reviewed scope

  • This report covers only Sompote/Tiger_bot at commit 370409497ac11e8fc5dde5e4667068ed0aacf0ae, acquired as immutable snapshot 92006138-0a9b-4f5b-b4ff-d21c7dbf4656 with SHA-256 2afafb3d7508fb8a56428cbdb418b539ca11bfd47b8f5fe3e62832d628b483dd.
  • The Inspector accounted for all 416 declared checks. The result set contains 184 pass results, 8 finding-status checks, 1 skipped result, 222 not-applicable results, and 1 error. These statuses describe deterministic checks, not a whole-artifact security verdict.
  • The 30 deterministic candidates are concentrated in a small number of review themes: credential transport and logging, subprocess and code-execution surfaces, randomness, install-time behavior, environment access, and package publication/configuration.
  • All 30 pinned machine finding identities remain represented exactly once through the existing finding assessments. This compose pass does not silently promote, dismiss, merge, or replace them.
  • The acquired snapshot contains 109 included files, 45 skipped entries, and 2 redactions. Conclusions do not extend to omitted material, Git history, submodules, Git LFS objects, or later upstream versions.
  • No target code, package lifecycle hook, test, binary, submodule, browser JavaScript, generated payload, or downloaded artifact was executed.

This conclusion is limited to the reviewed version and purpose. It is not a universal certification.

What remains unknown

  • The embedded research context contains machine finding IDs, check IDs, file hashes, and exact locations, but report_context.findings is empty and the relevant source excerpts are not embedded.
  • Credential-in-URL, credential-in-arguments, token-logging, and environment-access candidates cannot establish that a live secret is present or exposed without the underlying value and data-flow context.
  • Subprocess and code-analysis candidates do not establish command injection, privilege escalation, or unsafe execution without command construction, caller trust, argument provenance, PATH control, and privilege context.
  • The Math.random candidate is not a security defect by itself; impact depends on whether the generated value participates in authentication, authorization, secrecy, uniqueness, or another security-sensitive function.
  • The npm postinstall candidate establishes an install-time execution surface but not the behavior or risk of the invoked lifecycle command because its implementation is not present in the embedded context.
  • Public npm publication configuration describes package distribution behavior and is not itself a vulnerability.
  • Pass results apply only to their named deterministic conditions and inspected scope; they are not evidence that the surrounding code or artifact is safe.
  • Known-vulnerability coverage is unavailable because the pinned osv-offline adapter failed and no vulnerability database version is available.
  • The machine summary reports three skipped surfaces and one skipped check result. The snapshot also records 45 skipped entries and two redactions; those omissions are not assumed safe or irrelevant.
  • Git history, submodule contents, and Git LFS objects were not acquired, and no runtime behavior was exercised.
  • Because exact source excerpts are unavailable in this fallback context, the 30 deterministic candidates remain evidence leads rather than fully adjudicated editorial findings.
  • A safety rating cannot be defended from the available evidence. The 30 machine candidates are located and categorized, but exact source context is missing, the offline vulnerability adapter failed, and skipped or reduced surfaces remain unresolved.

Report history

Compose pass for report revision 3. Reworked the existing enriched Audit into a standalone reader-facing dossier with a clearer review boundary, candidate-family interpretation, methodology, limitations, and conclusion. Machine-owned Inspection identity and prior finding dispositions remain unchanged.

Technical review details

Inspection coverage

109 ordinary acquired files were included; 45 inventory entries were skipped. A passed check means only that its condition was not found in its inspected scope.

30 machine observations received analyst dispositions: 30 unresolved.

Method

inspection-review/1. Target code was not executed.

Convert the existing inspection-bound research into a concise technical dossier without changing machine-owned identity, manufacturing evidence, or treating scanner output as a verdict.

The compose pass preserves the existing evidence-bound dispositions and focuses the reader on what the detector families imply, what they do not establish, and which unresolved evidence gaps prevent a rating. No analyst-only finding is added because no new exact source range was registered through the private Inspection source interface.

Recorded check results

416 across 42 check groups

Export CSV
8 Matched1 Errors1 Skipped184 No match222 Not applicable

Check matches are not confirmed vulnerabilities. Not applicable and skipped are kept separate.

AI & agent boundaries

34 results

27 no match · 7 not applicable

6 check groups
GroupMatchedErrorsSkippedNo matchNot applicable
agent permissions00090
dynamic context00030
mcp00047
model output execution00030
prompt injection00050
rag00030

Code & supply chain

63 results

3 matched · 1 errors · 52 no match · 7 not applicable

13 check groups
GroupMatchedErrorsSkippedNo matchNot applicable
code analysis10000
command injection00060
deserialization00080
download execute00020
dynamic execution00040
dynamic loading00040
github actions00007
install scripts200140
known dependencies01000
remote loading00030
shell process00050
skills installation00030
template execution00030

Identity & sensitive data

59 results

5 matched · 1 skipped · 38 no match · 15 not applicable

10 check groups
GroupMatchedErrorsSkippedNo matchNot applicable
authentication00020
authorization000315
cryptography00040
environment access20020
filesystem00030
persistence00030
privacy logging10020
randomness10050
secrets101110
session handling00030

Network & web

33 results

13 no match · 20 not applicable

8 check groups
GroupMatchedErrorsSkippedNo matchNot applicable
hardcoded endpoints00010
network00020
network boundaries00008
tls00090
web configuration00010
web forms00002
web headers00005
website trust00005

Infrastructure

217 results

44 no match · 173 not applicable

4 check groups
GroupMatchedErrorsSkippedNo matchNot applicable
cloud configuration0000124
containers000420
iac00020
kubernetes000049

Acquisition & other checks

10 results

10 no match

1 check group
GroupMatchedErrorsSkippedNo matchNot applicable
acquisition000100

Cite this record

DiggingBeagle. Sompote/Tiger_bot. Published Audit revision 3; reviewed artifact SHA-256 2afafb3d7508fb8a56428cbdb418b539ca11bfd47b8f5fe3e62832d628b483dd. https://diggingbeagle.com/audits/sompote-tiger-bot-b2961480/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology