bookkeeping

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Anomaly
AnomalyLOW
tests/test_index.py

No direct malicious functionality (e.g., network exfiltration, credential theft, or system command execution) is evident in the shown snippet. The key security concern is the tier-2 test’s dynamic runtime import and execution of an external kg.py discovered via environment variables and default home/workspace paths. In untrusted or tampered environments, this mechanism could run attacker-controlled code during testing. Review the implementations of bookkeeping.cmd_index and the external kg.py source and ensure kg.py discovery is constrained/verified in real deployments.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Sep 7, 2026, 03:12 PM
Package URL
pkg:socket/skills-sh/broomva%2Fskills%2Fbookkeeping%2F@dc9453932a0bde6080b3a99e5e088dbeb919ccf21d6d203bd74da616077c06c0
Security Audit — socket — bookkeeping