beautiful-cli-design

Warn

Audited by Socket on Oct 4, 2026

1 alert found:

Anomaly
AnomalyLOW
references/08-gum-shell-prompts.md

The fragment appears to be CLI usage examples, not evident malware. However, the execSync wrappers use shell command strings with values that are not shell-escaped, creating command-injection risk if callers supply untrusted data. gumSpin explicitly accepts and executes a command. The safer pattern is to use spawnSync with an argument array and avoid shell execution where possible. The excerpt is incomplete, so this conclusion applies only to the visible code.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Oct 4, 2026, 02:23 PM
Package URL
pkg:socket/skills-sh/curiositech%2Fwindags-skills%2Fbeautiful-cli-design%2F@0e8c8dcb7727fd134e86bfc8564c1498d0ea4d7b2d7daa62d5b7d6d836c568ad
Security Audit — socket — beautiful-cli-design