agent-desk

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/examples.md

No direct evidence of malware, credential theft, or data exfiltration is present in the shown fragment; the content appears consistent with a planning/session automation harness. The primary security concern is the repeated use of scripts/browser.js exec eval to execute dynamically constructed code strings that invoke agentAPI methods in a browser/automation context. If any eval string components can be influenced by remote page state, persisted session content, or placeholder substitution, it could enable arbitrary code execution and misuse of the agentAPI’s state-changing capabilities. Review scripts/browser.js and the agentAPI bridge for strict control of eval inputs and robust input validation/sanitization; otherwise treat this pattern as a security alert.

Confidence: 46%Severity: 56%
Audit Metadata
Analyzed At
Aug 24, 2026, 11:15 AM
Package URL
pkg:socket/skills-sh/galiprandi%2Fskills%2Fagent-desk%2F@2fe3427aa7ffafee11782ad8161910648f74cc48245e2ba86e4cefcb324908f5
Security Audit — socket — agent-desk