service-omni-supervisor-surface-deploy

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/tests/_bootstrap.py

This module is primarily deployment/test orchestration code: it executes an internal Bash script with caller-influenced arguments and a caller-modifiable environment (notably PATH). It also supports creating a temporary executable shim named `sf`, intended for testing/scrubbing, which can redirect downstream behavior if PATH includes the temp directory. The provided fragment contains no explicit evidence of network exfiltration or credential theft in Python itself, but the combination of external script execution, PATH manipulation, and executable shim creation is a meaningful security risk that cannot be fully assessed because the referenced shell script and the full `_FAKE_SF` definition are not included in the snippet.

Confidence: 43%Severity: 52%
Audit Metadata
Analyzed At
Sep 6, 2026, 01:12 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fservice-omni-supervisor-surface-deploy%2F@295f2e9ff0859c05ec53648ef7cd48319a4dcd5ad3ec81216af1cb84dc8da56a
Security Audit — socket — service-omni-supervisor-surface-deploy