nightly-eval-investigation

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/publish_report.ts

No clear signs of overt malware are present in this fragment. The dominant concern is security of the automation environment: it heavily uses `execSync` with template-literal shell commands that interpolate potentially external variables (especially parent/sub-issue URLs). Without strict sanitization/escaping, this creates a plausible command-injection/sabotage path in CI/runner contexts. Separately, parsed audit text is propagated into GitHub issue bodies and project fields, which can enable integrity abuses (malicious content in downstream operational artifacts).

Confidence: 60%Severity: 60%
Audit Metadata
Analyzed At
Aug 22, 2026, 11:15 PM
Package URL
pkg:socket/skills-sh/googlechrome%2Fmodern-web-guidance-src%2Fnightly-eval-investigation%2F@cc03226bcc6d6cddc1f6199b3754d614f95bf5a065c7c28a29f3e4e498a082ee
Security Audit — socket — nightly-eval-investigation