magi
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
AnomalyAnomalyreferences/scripts/tests/fixtures/sages-prompt-in-argv.json
LOWAnomalyLOW
references/scripts/tests/fixtures/sages-prompt-in-argv.json
This module is a crafted shell-execution test configuration that would leak a templated prompt/argument value to stdout (and possibly via argv visibility) if it is executed. There is no direct evidence of covert malware (e.g., networking or persistence) in the fragment itself, but the design uses high-risk "sh -c" plus argument templating to create a sensitive-data exposure scenario. Proper config validation that rejects this payload is essential; otherwise the impact is meaningful information disclosure.
Confidence: 72%Severity: 55%
Audit Metadata