huashu-agent-swarm
Audited by Socket on Sep 15, 2026
4 alerts found:
Securityx3AnomalyThe fragment appears intended as a swarm-monitoring dashboard, not as overt malware. However, it has high security risk: unauthenticated network exposure, sensitive project-data disclosure, privileged Git push behavior, and multiple shell-injection paths, especially through the /api/input message. It is also syntactically incomplete as supplied and would not execute without correction.
This is an autonomous repository-agent instruction template, not conventional package code. It does not itself contain clear malware or an embedded malicious payload, but it creates a high-impact supply-chain risk by granting unrestricted shell and Git access and executing HUMAN_INPUT.md instructions without validation or human approval. The main concern is unauthorized code modification and publication through git push, especially when the input file can be tampered with.
No direct malware such as credential harvesting, suspicious network exfiltration, reverse-shell behavior, or obfuscated payloads is present. However, the script grants an AI agent unrestricted execution and automatically pushes resulting changes to origin/main, creating a substantial supply-chain and repository-integrity risk if the prompt, repository, model interaction, or runtime environment is compromised. It should not be run in a trusted development environment without isolation, review gates, and restricted Git credentials.
代码表现为用于停止 Agent 协作环境并清理 Git worktree 的管理脚本,没有明确恶意行为或供应链攻击迹象。主要风险来自其预期的破坏性操作:合并失败后仍强制删除 worktree 和分支,以及根据通配符递归删除目录。应在确认项目路径、匹配目录和合并结果后执行,或在清理前中止于合并冲突。