persist
Audited by Socket on Sep 7, 2026
2 alerts found:
AnomalySecuritySUSPICIOUS. The skill’s core behavior is mostly aligned with its stated purpose of long-horizon restart loops, and the flagged `/.config` access appears to be benign local state storage. The main risk is proportionality: it enables repeated autonomous agent execution with fresh contexts and relies on a transitive skill-install chain, so overall risk is medium even without clear malware or exfiltration.
No clear evidence of a built-in backdoor, network exfiltration, or data-theft. However, the module intentionally executes external commands using subprocess.run(..., shell=True) with a command string built from user-controlled agent-cmd and prompt contents. This is a high-impact command-injection/supply-chain execution risk in any context where attacker-controlled inputs can reach prompt_file contents or agent-cmd. Additional medium risk includes arbitrary file reads via grep: success-condition and filesystem redirection via BROOMVA_PERSIST_HOME.