security-scan

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
references/finding-detail-fields.md

There is a concrete, defendable vulnerability in the environment management flow: the runtime upsert path accepts caller-controlled keys and inserts into the shared environments map without reapplying the startup reserved-ID guard. This enables an attacker to override the manager-owned local environment, causing default environment resolution to point to a malicious executor. The risk is medium-to-high depending on RPC exposure and privilege of the attacker boundary; remediation should enforce reserved-ID checks in runtime insertion and align runtime behavior with startup invariants.

Confidence: 45%Severity: 65%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:10 PM
Package URL
pkg:socket/skills-sh/ahgraber%2Fskills%2Fsecurity-scan%2F@56190c9f638afbb68df41996fef6c0bf625cca66c617c86905aed05305b6719f
Security Audit — socket — security-scan