android-build

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/build.sh

No explicit malware payload (no network access, credential theft, persistence, or exfiltration) is evident in this script fragment. However, the script has a high-impact security weakness: it performs shell evaluation via eval echo $path on export.path_priority[] values sourced from .androidbuild.yml. If an attacker can modify or influence that YAML (a realistic supply-chain/config-injection threat), they can execute arbitrary commands in the build environment and write artifacts to attacker-chosen paths, with additional operational risk from optional diskutil eject.

Confidence: 70%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/coderfee%2Fai%2Fandroid-build%2F@5ac33846862894a2b1ef249abe1979206485310a