briefing-followup
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyscripts/briefing-followup/action-orchestrate.sh
LOWAnomalyLOW
scripts/briefing-followup/action-orchestrate.sh
The fragment appears to be an orchestration wrapper rather than malware. It contains no direct data theft, persistence, reverse shell, or obfuscated payload. However, it invokes an external Claude agent with --dangerously-skip-permissions and accepts largely unsanitized prompt input, creating a meaningful prompt-injection risk. The unsanitized ticket in the background log path also permits potential path traversal or malformed-path behavior. Input validation, safe filename encoding, and avoiding --dangerously-skip-permissions are recommended.
Confidence: 96%Severity: 67%
Audit Metadata