ghost-exo

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/exo-skill.py

No clear evidence of intentional malware or supply-chain sabotage is present. The code is a conventional authenticated skill upload/download client. It has a notable arbitrary file write/path traversal weakness during download because API-provided paths are not normalized and constrained to the output directory. Risk is primarily dependent on the trustworthiness of EXO_API_URL and its responses.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 4, 2026, 04:34 AM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-exo%2F@1f586bdcf08f5f1b29ac4c7fb13d6928374c3b38968a21e53cab7abcbe805b8e
Security Audit — socket — ghost-exo