loki-mode

Warn

Audited by Socket on Sep 14, 2026

3 alerts found:

Securityx3
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The external install path is mostly coherent and same-org official, but the skill’s core operating model is disproportionate: it demands bypassed permissions, forbids confirmation, and enables broad autonomous real-world actions far beyond a narrowly scoped coding helper. Main risk is unsafe autonomy and safety-control bypass, not confirmed malware.

Confidence: 93%Severity: 74%
SecurityMEDIUM
autonomy/run.sh

Moderate-to-high supply-chain risk. The script is an autonomous runner that repeatedly executes Claude Code with `--dangerously-skip-permissions`, which strongly increases the impact of any compromised/malicious agent behavior, prompt injection in PRD/docs/ledger context, or manipulated local state. It also serves a local dashboard that renders unescaped JSON into `innerHTML`, enabling DOM XSS if queue/agent data is attacker-controlled. No direct credential theft or network exfiltration is evident in the provided fragment, but the autonomy/policy bypass combination warrants thorough review and sandboxing/permission hardening.

Confidence: 72%Severity: 75%
SecurityMEDIUM
benchmarks/results/2026-01-05-00-49-17/humaneval-solutions/160.py

This code is highly unsafe because it builds a Python expression string from caller-controlled `operator` and `operand` values and passes it directly to `eval()`. Without strict allowlisting of operators and strict numeric validation of operands, it enables arbitrary code execution (RCE) in the Python process. Treat as critical security risk and avoid using in any context where inputs can be influenced by an attacker.

Confidence: 90%Severity: 95%
Audit Metadata
Analyzed At
Sep 14, 2026, 02:31 PM
Package URL
pkg:socket/skills-sh/claudiodearaujo%2Fizacenter%2Floki-mode%2F@26fd5d514c2d33c88122ec170b0a3bce75a4639c47281b4f4b934559b2dfe96a
Security Audit — socket — loki-mode