pi-session-query

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/query.py

This module is primarily a local JSONL session query/summarization tool, but it also functions as a Python “query runner” by executing caller-supplied code via exec() in an unsandboxed environment. While there is no direct evidence of covert malware in the fragment itself (no network/exfiltration logic, no file corruption, no obvious credential theft), the exec sink makes the package highly risky in any supply-chain or automation scenario where an attacker could influence the provided script/inline code/stdin or otherwise affect what code gets executed. Optional toon_format import adds additional behavioral variability but is not shown to be malicious within this file.

Confidence: 72%Severity: 88%
Audit Metadata
Analyzed At
Jul 24, 2026, 02:56 AM
Package URL
pkg:socket/skills-sh/CNife%2Fskills%2Fpi-session-query%2F@1b388762ec4d0a19ab9229fa7d2b14349d5d0fbccc80d0144fb9292e26e6c233
Security Audit — socket — pi-session-query