frontierharness-eval

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/trial-worker.sh

This is a task-runner script whose core behavior is intentional command execution. It is not inherently malware based on the supplied fragment, but it becomes high risk if an attacker can control the command argument, state path, FH_WORK_DIR, or relevant filesystem contents. The direct bash -lc invocation and lack of input validation should be treated as an authorization boundary requiring trusted callers or strong sandboxing.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 8, 2026, 07:36 PM
Package URL
pkg:socket/skills-sh/frontier-harness-eval%2Feval%2Ffrontierharness-eval%2F@6a54c73745d392211bd8e546c15ce2fff1159d5ef50a25b9342ce168e021ffdb
Security Audit — socket — frontierharness-eval