ghost-exo
Warn
Audited by Socket on Sep 4, 2026
1 alert found:
AnomalyAnomalyscripts/exo-skill.py
LOWAnomalyLOW
scripts/exo-skill.py
No clear evidence of intentional malware or supply-chain sabotage is present. The code is a conventional authenticated skill upload/download client. It has a notable arbitrary file write/path traversal weakness during download because API-provided paths are not normalized and constrained to the output directory. Risk is primarily dependent on the trustworthiness of EXO_API_URL and its responses.
Confidence: 98%Severity: 58%
Audit Metadata