magi

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Anomaly
AnomalyLOW
references/scripts/tests/fixtures/sages-prompt-in-argv.json

This module is a crafted shell-execution test configuration that would leak a templated prompt/argument value to stdout (and possibly via argv visibility) if it is executed. There is no direct evidence of covert malware (e.g., networking or persistence) in the fragment itself, but the design uses high-risk "sh -c" plus argument templating to create a sensitive-data exposure scenario. Proper config validation that rejects this payload is essential; otherwise the impact is meaningful information disclosure.

Confidence: 72%Severity: 55%
Audit Metadata
Analyzed At
Jul 30, 2026, 07:30 AM
Package URL
pkg:socket/skills-sh/anyoneanderson%2Fagent-skills%2Fmagi%2F@675be34284c19d09576ef4f7253ebd968848b9bfa64a6139880200c69792aebd
Security Audit — socket — magi