Python Security Injection and IO Audit Bundle
Run a read-only Python security audit focused on injection, unsafe dynamic execution, SSRF, path traversal, archive extraction, deserialization, logging, redirects, XML and XPath, regular expressions, and untrusted input flows.
This bundle runs 37 read-only Python security audit codemods. It is part of the split Python security audit set; run the other Python security audit bundles when you need broader coverage.
Included Codemods
- @codemod/python-agent-arg-injection-mining@0.1.0
- @codemod/python-agent-conn-string-injection@0.1.0
- @codemod/python-agent-path-injection-audit@0.1.0
- @codemod/python-agent-sql-injection-mining@0.1.0
- @codemod/python-agentic-code-injection-audit@0.1.0
- @codemod/python-agentic-command-injection@0.1.0
- @codemod/python-agentic-ssrf-workflow-audit@0.1.0
- @codemod/python-ai-code-exec-sandboxing@0.1.0
- @codemod/python-command-injection-audit@0.1.0
- @codemod/python-detect-xml-parser-xxe-risk@0.1.0
- @codemod/python-dynamic-code-injection-audit@0.1.0
- @codemod/python-dynamic-sql-injection-detection@0.1.0
- @codemod/python-dynamic-sql-query-formatting@0.1.0
- @codemod/python-filesystem-path-oracle-access@0.1.0
- @codemod/python-http-header-injection@0.1.0
- @codemod/python-insecure-temp-file-creation@0.1.0
- @codemod/python-log-forging-injection-sinks@0.1.0
- @codemod/python-no-stacktrace-disclosure@0.1.0
- @codemod/python-nosql-injection-hotspots@0.1.0
- @codemod/python-path-injection-io-mining@0.1.0
- @codemod/python-privileged-prompt-injection@0.1.0
- @codemod/python-redos-regex-risk-audit@0.1.0
- @codemod/python-reflected-input-response-xss@0.1.0
- @codemod/python-ssrf-outbound-request-miner@0.1.0
- @codemod/python-ssrf-path-traversal-sinks@0.1.0
- @codemod/python-template-autoescaping-disabled@0.1.1
- @codemod/python-template-injection-from-input@0.1.0
- @codemod/python-torch-load-unsafe-pickle@0.1.0
- @codemod/python-untrusted-allocation-size@0.1.0
- @codemod/python-untrusted-deserialization-audit@0.1.0
- @codemod/python-untrusted-env-mutation@0.1.0
- @codemod/python-untrusted-loop-bounds@0.1.0
- @codemod/python-untrusted-process-args-check@0.1.0
- @codemod/python-untrusted-redirect-targets@0.1.0
- @codemod/python-world-readable-writable-modes@0.1.1
- @codemod/python-xpath-injection-miner@0.1.0
- @codemod/python-zip-slip-archive-extract-audit@0.1.0