atai-rare-event-detection-agent

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
references/run_red_agent.py

No direct evidence of intentional malware (no eval/exec, no subprocess/persistence, no credential harvesting beyond using an intended API key). However, this module has meaningful security risks: it will fetch a remote-provided HTTP URL without host allowlisting (SSRF-like behavior) and then write the fetched bytes to an arbitrary user-controlled local path (--output) without validation. In threat models where the remote ref can be influenced (compromised service/MITM/abuse of upstream), these behaviors could enable SSRF and arbitrary file overwrite. Use only with trusted endpoints/responses and constrain --output in operational environments.

Confidence: 66%Severity: 58%
Audit Metadata
Analyzed At
Aug 25, 2026, 09:57 PM
Package URL
pkg:socket/skills-sh/archetypeai%2Fagent-skills%2Fatai-rare-event-detection-agent%2F@f139c088f498da7df56b972c57ee288f07b20b7eaccfb6156caa694bfc104ff9
Security Audit — socket — atai-rare-event-detection-agent