war-room

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
modules/expert-roles.md

No explicit malware, backdoor, credential theft, or network exfiltration behavior is visible in this module. However, it constructs and encourages execution of external CLIs with a clearly permission-bypass style flag ('--dangerously-skip-permissions') and includes a fallback that may execute a binary from a user-writable directory (~/ .local/bin). This is a moderate-to-high operational security risk if the environment is tampered with or if the invoked tools have broad capabilities when run with reduced safeguards. Additional review is needed of the consuming subprocess execution code and the behavior of the invoked expert CLIs.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
May 11, 2026, 12:02 PM
Package URL
pkg:socket/skills-sh/athola%2Fclaude-night-market%2Fwar-room%2F@6235afec1b029dbade1f769552cbe1db6cb5648a
Security Audit — socket — war-room