qa-fleet

Warn

Audited by Socket on Jul 12, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/launch-fleet.sh

No direct malware or obvious sabotage logic is present in this launcher script (no eval/dynamic execution, no network exfiltration, no system command spawning beyond running codex). However, it sources an external config script and executes an external “codex” tool with -s danger-full-access, feeding it per-bundle prompt content from files. If an attacker can influence CAPTAIN_CONFIG or the prompt/bundle files, they could cause the codex executor to perform harmful actions. Additionally, bundle names are not sanitized before being used in filenames/paths, which may enable unintended filesystem effects. Overall: likely benign orchestration, but with meaningful supply-chain/execution-trust risk due to high-privilege downstream invocation and untrusted inputs.

Confidence: 68%Severity: 52%
Audit Metadata
Analyzed At
Jul 12, 2026, 05:55 AM
Package URL
pkg:socket/skills-sh/dolessHQ%2Fself-obsolescence%2Fqa-fleet%2F@b44772eddf4d3230cdb82b0372ebbf29723463a426afe86194cfec3833e2eb89
Security Audit — socket — qa-fleet