skill-system-tkt

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/tkt.sh

This code is a local orchestration CLI that performs multiple high-impact actions. The strongest supply-chain/sabotage concern is intentional host command execution: acceptance_criteria.run from YAML is executed with shell=True during bundle close, and close_gate.command from config is executed via bash -lc. These are dangerous sinks if an attacker can influence ticket YAMLs or configuration. File writes are extensive under a directory that can be influenced via environment variables (TKT_ROOT), increasing persistence risk via symlinks/path manipulation. No clear obfuscation or direct credential theft is present, so malware probability is lower; however, the command-execution capability makes security risk significant.

Confidence: 74%Severity: 72%
Audit Metadata
Analyzed At
Apr 11, 2026, 12:56 AM
Package URL
pkg:socket/skills-sh/arthur0824hao%2Fskills%2Fskill-system-tkt%2F@8aa3409917a73de279815367f711264cc7410519