<< Back to security report
──gptomics/bioskills/loop-calling — semgrep Scan
Repositorygptomics/bioskills →
Commitd91ed3d →
VerdictFAIL
Score0
DateSep 17, 2026
──Findings
SeverityRuleMessageFile:Line
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/comparative-genomics/ortholog-inference/examples/ortholog_analysis.py:33 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/comparative-genomics/ortholog-inference/examples/ortholog_analysis.py:113 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/comparative-genomics/synteny-analysis/examples/synteny_analysis.py:58 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/comparative-genomics/synteny-analysis/examples/synteny_analysis.py:65 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/comparative-genomics/synteny-analysis/examples/synteny_analysis.py:81 →
MEDIUMpython.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detectedDetected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.gptomics/bioskills/loop-calling-ff6287b3/database-access/geo-data/examples/search_geo.py:32 →
MEDIUMpython.lang.security.deserialization.pickle.avoid-pickleAvoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.gptomics/bioskills/loop-calling-ff6287b3/gene-regulatory-networks/scenic-regulons/examples/pyscenic_workflow.py:73 →
MEDIUMpython.lang.security.deserialization.pickle.avoid-pickleAvoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.gptomics/bioskills/loop-calling-ff6287b3/genome-engineering/off-target-prediction/examples/off_target_analysis.py:56 →
MEDIUMpython.lang.security.deserialization.pickle.avoid-pickleAvoid using `pickle`, which is known to lead to code execution vulnerabilities. When unpickling, the serialized data could be manipulated to run arbitrary code. Instead, consider serializing the relevant data as JSON or a similar text-based serialization format.gptomics/bioskills/loop-calling-ff6287b3/genome-engineering/off-target-prediction/examples/off_target_analysis.py:58 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/liquid-biopsy/cfdna-preprocessing/examples/preprocess_cfdna.py:42 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/liquid-biopsy/cfdna-preprocessing/examples/preprocess_cfdna.py:60 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/liquid-biopsy/ctdna-mutation-detection/examples/detect_ctdna_mutations.py:36 →
MEDIUMpython.lang.security.audit.dynamic-urllib-use-detected.dynamic-urllib-use-detectedDetected a dynamic value being used with urllib. urllib supports 'file://' schemes, so a dynamic value controlled by a malicious actor may allow them to read arbitrary files. Audit uses of urllib calls to ensure user data cannot control the URLs, or consider using the 'requests' library instead.gptomics/bioskills/loop-calling-ff6287b3/structural-biology/structure-io/examples/download_structure.py:20 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/workflows/liquid-biopsy-pipeline/examples/liquid_biopsy_pipeline.py:43 →
HIGHpython.lang.security.audit.subprocess-shell-true.subprocess-shell-trueFound 'subprocess' function 'run' with 'shell=True'. This is dangerous because this call will spawn the command using a shell process. Doing so propagates current shell settings and variables, which makes it much easier for a malicious actor to execute commands. Use 'shell=False' instead.gptomics/bioskills/loop-calling-ff6287b3/workflows/liquid-biopsy-pipeline/examples/liquid_biopsy_pipeline.py:104 →