select-models
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
SecuritySecurityscripts/validate.sh
MEDIUMSecurityMEDIUM
scripts/validate.sh
The code is a command-template validator, but it executes the supplied template as unrestricted Bash code. This is an intentional arbitrary-command-execution design and constitutes a high security risk when template input is untrusted or the script has meaningful privileges. No clear credential theft, persistence, network exfiltration, or other malware behavior is present in the fragment. The predictable /tmp/validate.err file is an additional filesystem safety concern.
Confidence: 99%Severity: 88%
Audit Metadata