dcg

Fail

Audited by Socket on Jun 3, 2026

1 alert found:

Malware
MalwareHIGH
tests/golden/artifacts/explain/heredoc_python_rmtree.json

This fragment is a destructive operation: it unconditionally deletes `/home/example/project` recursively via `shutil.rmtree()` executed through an inline `python3` heredoc. While no exfiltration or credential theft is present in the shown code, the lack of safety checks and hardcoded absolute path make it strongly indicative of potential sabotage in a build/install context. Additional surrounding code/installer context is needed to confirm whether it is legitimate cleanup or malicious behavior.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Jun 3, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/Dicklesworthstone%2Fdestructive_command_guard%2Fdcg%2F@4a5306d7859417352209c9cf3c599291c15da2ce
Security Audit — socket — dcg