claw-shell-hardened
Fail
Audited by Socket on Apr 21, 2026
1 alert found:
MalwareMalwarehandler.js
HIGHMalwareHIGH
handler.js
High-risk arbitrary command execution via a persistent tmux session. The only mitigation is a weak, easily bypassed blacklist and incomplete escaping. The module both executes attacker-controlled commands and returns command output, enabling data disclosure and potential persistence. This should be treated as a critical security concern unless access is strictly controlled and the command source is fully trusted.
Confidence: 88%Severity: 97%
Audit Metadata