syllabus

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/citation_tracker.py

The code is a readable local session-tracking CLI with no evident malicious behavior. It contains a genuine path traversal/arbitrary file read-write risk because the user-controlled session name is not validated before being used as a filesystem path. Restrict session names to safe filename characters, resolve and verify paths remain within SESSIONS_DIR, and use safer atomic file handling. The risk is security-relevant but not indicative of malware.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 02:43 PM
Package URL
pkg:socket/skills-sh/alirezarezvani%2Fclaude-skills%2Fsyllabus%2F@766684fa22be009e6ac8f28745ac28b1f0b80ecad13e93e613e313964bb3fca1
Security Audit — socket — syllabus