token-saver
Warn
Audited by Socket on Jun 16, 2026
1 alert found:
AnomalyAnomalyaudit.json
LOWAnomalyLOW
audit.json
No clear indicators of overt malware (e.g., exfiltration, credential theft, or command execution) are present in the provided findings. However, the combination of (1) potential directory-escape/path traversal-style resolution, (2) home-directory access, (3) persistence/config writes to AGENTS.md/memory artifacts, and (4) LLM prompt-control/sandbox-boundary manipulation via a 'SYSTEM:'-like delimiter is a meaningful supply-chain security risk that warrants code-level verification of path allowlists, strict write targets, and prompt-construction safety controls. If those constraints are enforced, risk may be reduced; if not, it should be treated as a moderate-to-high integrity/privacy concern.
Confidence: 100%Severity: 60%
Audit Metadata