codeart2d

Warn

Audited by Socket on Oct 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/forge_nav.py

The code primarily implements map navigation and collision processing. It has a concrete path traversal issue: untrusted bundle paths can resolve outside the bundle directory and be read. No direct evidence of malware or data exfiltration appears in the supplied fragment. The fragment is truncated, limiting assessment.

Confidence: 98%Severity: 53%
Audit Metadata
Analyzed At
Oct 8, 2026, 01:18 AM
Package URL
pkg:socket/skills-sh/0x0funky%2Fagent-sprite-forge%2Fcodeart2d%2F@31f6db2c2e9be479f1430a54a71944ddc78681ca4276dbc7f27c2870e81bffd6