team-swarm

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/scoring.py

This code is primarily a scoring/verification utility, but it contains a high-impact supply-chain / arbitrary code execution mechanism: ScriptScorer dynamically loads and executes Python code from rule_path using spec.loader.exec_module without sandboxing or integrity controls. If rule_path and the loaded file are not strictly trusted and access-controlled, the host application is vulnerable to executing malicious logic. Other concerns include a likely bug in hallucination_check ('threshol' typo) and potential information leakage via printing exception details. No direct malware behaviors (e.g., network exfiltration) are visible in this snippet beyond enabling execution through the plugin mechanism.

Confidence: 71%Severity: 78%
Audit Metadata
Analyzed At
Sep 3, 2026, 12:17 PM
Package URL
pkg:socket/skills-sh/catlog22%2Fmaestro-flow%2Fteam-swarm%2F@e7155b6cc9331c2a1279a3e4e7292256d21dcdfaeca9377a47f1d735b864acb8