minions

Warn

Audited by Socket on Jul 9, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/minions-wait.mjs

Within this module, there is no direct evidence of stealthy malware (no network exfiltration, credential theft, persistence, or destructive actions). However, the wrapper executes a JavaScript companion script discovered in a user-writable HOME cache directory, and therefore inherits any maliciousness present in that companion file (or tampering of that cache). It also trusts companion-provided JSON fields (including logFile paths) for control decisions, though it only reads metadata. Overall risk is driven primarily by local/code-execution trust-model weakness rather than by in-module malicious logic.

Confidence: 63%Severity: 52%
Audit Metadata
Analyzed At
Jul 9, 2026, 05:48 PM
Package URL
pkg:socket/skills-sh/djalmajr%2Fskills%2Fminions%2F@859a5183c5873a4ffd72a630cac7850418567c316e30a00d68fd5e7e181a7733
Security Audit — socket — minions