aha

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
cli/src/share.mjs

The code implements a recognizable local sharing feature using cloudflared and does not show clear malicious behavior. It does execute external programs and downloads an executable without checksum or signature verification, creating a supply-chain and PATH-hijacking risk. The selected directory is intentionally exposed through a public temporary tunnel, so use with sensitive directories presents a significant data exposure risk. Malware likelihood is low, while operational security risk is moderate.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:00 AM
Package URL
pkg:socket/skills-sh/dimples-wiki%2Fagent-skills%2Faha%2F@0dcd0d268d87ab5e56e90d247407cc216766012ea4c3ef18138050ef42174042
Security Audit — socket — aha