remote-agents

Warn

Audited by Socket on Sep 18, 2026

6 alerts found:

Anomalyx6
AnomalyLOW
scripts/install-work-bridge-service.py

The fragment is a privileged WireGuard service installer with expected persistence and sudoers behavior for a bridge application. It does not directly show malware or data exfiltration. However, it installs root-level boot services and passwordless service-control rules, and it trusts several configuration-derived paths and identifiers with limited validation. The supplied code is also syntactically incomplete because both run-script assignments lack a value; the omitted script must be reviewed before approving the installer, especially for command execution and network behavior.

Confidence: 97%Severity: 62%
AnomalyLOW
scripts/lib/devlocal.py

The code implements legitimate-looking remote desktop, WireGuard, SMB, and process-control functionality. It contains no clear malware, exfiltration, persistence, or hardcoded secret indicators. Security concerns are significant where configuration values reach shell=True or an unescaped PowerShell command, and the fragment also contains an apparent syntax error in the macOS credential lookup. Use only with trusted configuration and fix the command-construction and syntax issues.

Confidence: 96%Severity: 62%
AnomalyLOW
scripts/verify-qa-vision.py

The fragment appears to be a desktop/MCP visual QA harness. It performs extensive local file I/O, GUI interaction, screenshot capture, and execution of externally configured Python and agent binaries. No direct malicious payload, data exfiltration, credential theft, persistence, or destructive behavior is evident. Security risk is moderate because attacker-controlled environment variables can redirect the MCP server, agent executable, interpreter, and output directory, and the agent is run with --always-approve. The behavior of those external components requires separate review.

Confidence: 95%Severity: 56%
AnomalyLOW
scripts/Start-Interactive.ps1

The code is a readable administrative launcher and shows no clear malicious behavior, obfuscation, data theft, or unauthorized network activity. It does create and remove a scheduled task to launch caller-selected code as an interactive user, which is a significant capability and should be restricted to trusted callers. The main risk is arbitrary code execution with the selected user's privileges if the parameters are externally controllable.

Confidence: 98%Severity: 58%
AnomalyLOW
scripts/Start-VisualQa.ps1

The fragment is a readable task-dispatch wrapper with no clear malicious behavior, credential theft, network exfiltration, or obfuscated payload. It intentionally launches a configurable Python program as an interactive user, defaulting to Administrator, so it is security-sensitive and should only be callable by trusted principals with trusted input files and paths. The absence of task cleanup and incomplete output-path validation warrant review but do not by themselves indicate malware.

Confidence: 96%Severity: 62%
AnomalyLOW
references/examples/controller-policy.example.json

The supplied fragment is a readable AWS IAM policy, not executable code, and contains no apparent malware or obfuscation. It grants substantial administrative access to one EC2 host through SSM, including arbitrary shell/PowerShell command execution, interactive SSH access, port forwarding, and command-output retrieval. Resource scoping reduces blast radius, but the policy remains high impact if the principal or credentials are compromised. The placeholders must be replaced and resource/session scoping should be verified before deployment.

Confidence: 99%Severity: 68%
Audit Metadata
Analyzed At
Sep 18, 2026, 09:15 PM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fpragmatic-orchestration%2Fremote-agents%2F@006baaeb6ebcb9216a82ec17243189bef86d98a3607975716bed6ab57e629796
Security Audit — socket — remote-agents