cloud-weaver-pre-flight-check

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/preflight.py

The code does not show clear malware or direct data exfiltration. It contains significant operational and supply-chain risks: automatic execution of an unpinned npx update and automatic staging, unsigned committing, pulling, and pushing of repository changes. These actions should require explicit user consent, use pinned and verified dependencies, and avoid publishing changes implicitly. The sensitive-file check is defensive but filename-only.

Confidence: 97%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/fagnerlopes%2Fcloud-weaver%2Fcloud-weaver-pre-flight-check%2F@b167971e86042ecb8f32879f6263a59c39d7ffe9dcd8d6fdc8c195c99eec5554
Security Audit — socket — cloud-weaver-pre-flight-check