dyno-run-debug

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
dyno/fixtures/.claude/settings.json

No direct malicious code is present; this is a declarative permissions policy. However, it grants broad ability to execute Node/npx/bash-like commands and run file/content inspection utilities (cat/jq/ls) along with Read/Glob/Grep. This is not inherently malicious, but it significantly increases risk if the surrounding system can execute untrusted instructions under these permissions. Review the consumer/runner logic and enforce least-privilege and strict input/command mediation.

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Jul 7, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/dynobox%2Fskills%2Fdyno-run-debug%2F@4d403e85be31f8fad4d89027c39be4bcf7b0dae61e5f611d5ac8179a6a79ab51
Security Audit — socket — dyno-run-debug