outbound-engine

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/competitive-monitor.py

No clear evidence of intentional malware/backdoor activity in the provided fragment. The dominant risks are supply-chain-impacting operational vulnerabilities: configuration-driven outbound URL fetching (SSRF-like risk if an attacker can influence the competitor config) and potential path traversal/arbitrary file overwrite through unsanitized company_key used in snapshot filenames. If config/CLI inputs are fully trusted and company keys are constrained to safe characters, risk is reduced; otherwise, the module warrants review and hardening (URL allowlisting, company_key sanitization, and safer path construction).

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Aug 19, 2026, 07:47 PM
Package URL
pkg:socket/skills-sh/bighardperson%2Fcomputer-science-skills-collection%2Foutbound-engine%2F@601fd446752b8b98102decdc8dc495dee2e06b0d17a792031c8f808791a15849
Security Audit — socket — outbound-engine