pi-extensions

Warn

Audited by Socket on Jul 2, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
PATTERNS.md

No explicit malware behavior (e.g., backdoor, reverse shell, or direct exfiltration) is demonstrated in the provided snippets. However, the examples highlight security-sensitive, misuse-capable primitives—especially an override of a built-in 'read' tool performing arbitrary path filesystem reads, and a bash command rewriting/interception surface that can change executed commands. External search engine integration and provider/OAuth credential handling further expand the trust boundaries. Treat this as capability-rich code requiring strong safeguards (path allowlisting/sandboxing, robust command allowlisting/quoting, and secret-handling discipline) in the real package implementation.

Confidence: 42%Severity: 52%
SecurityMEDIUM
scripts/pi-skill-registry.ts
Audit Metadata
Analyzed At
Jul 2, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/Dwsy%2Fpi-extensions-skill%2Fpi-extensions%2F@35ee2882e98f3fb768f9778139b982c5fb17609c
Security Audit — socket — pi-extensions