select-models

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate.sh

The code is a command-template validator, but it executes the supplied template as unrestricted Bash code. This is an intentional arbitrary-command-execution design and constitutes a high security risk when template input is untrusted or the script has meaningful privileges. No clear credential theft, persistence, network exfiltration, or other malware behavior is present in the fragment. The predictable /tmp/validate.err file is an additional filesystem safety concern.

Confidence: 99%Severity: 88%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:54 PM
Package URL
pkg:socket/skills-sh/a-canary%2Farc-skills%2Fselect-models%2F@9fbd07b4e45f92562e5d72bfa2162d548dc2fcc9d1a4626cb0d2ec02ec029528
Security Audit — socket — select-models