agentic-evals

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
src/regressions.py

The code is an otherwise readable regression-audit utility with no direct evidence of malware or data exfiltration. Its significant security risk is intentional command execution from the JSON field fail_before_fix.proof_command, combined with an uncontrolled working directory. This is acceptable only when registry contents are trusted and reviewed; untrusted registry data could enable arbitrary command execution and path escape. The fragment also appears incomplete syntactically at the end.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fagentic-evals%2F@76e1964c7785fbf54f0533f1641f1c15842a13b077910c77ba79da6478da4148
Security Audit — socket — agentic-evals