google-form-callback

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/process-callback-candidates.mjs

No direct evidence of intentional malware (no obfuscation, no self-propagation, no reverse shell-like behavior) is present in this fragment. However, it has two major high-impact security risks: (1) it can execute an arbitrary, caller-configured binary via spawnSync (--calle-bin/--calle-arg*), and (2) it can exfiltrate an environment-derived token by POSTing it in the request body to a caller-controlled writeback URL. If CLI options, state/input paths, or environment variables are not strictly trusted, treat this module as potentially dangerous from an operational/supply-chain misuse standpoint.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Aug 4, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/CALLE-AI%2Fawesome-phone-call-agents%2Fgoogle-form-callback%2F@07647bdbab1e0d945c1f6feb663a78224bd3b035c256c087d837291d66e93733
Security Audit — socket — google-form-callback