beautiful-cli-design
Warn
Audited by Socket on Oct 4, 2026
1 alert found:
AnomalyAnomalyreferences/08-gum-shell-prompts.md
LOWAnomalyLOW
references/08-gum-shell-prompts.md
The fragment appears to be CLI usage examples, not evident malware. However, the execSync wrappers use shell command strings with values that are not shell-escaped, creating command-injection risk if callers supply untrusted data. gumSpin explicitly accepts and executes a command. The safer pattern is to use spawnSync with an argument array and avoid shell execution where possible. The excerpt is incomplete, so this conclusion applies only to the visible code.
Confidence: 96%Severity: 58%
Audit Metadata