corpus-report

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
corpus_report/__main__.py

This file itself is not demonstrably malicious, but it is high risk from a supply-chain perspective because it triggers import-time execution and immediately calls an imported app() callable. The real security posture depends on the .cli module implementation; audit .cli for network activity, environment or secret access, subprocesses, or obfuscation. Also correct the apparent truncation and avoid module-level invocation to reduce accidental execution on import.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fcorpus-report%2F@f85ccc83ce341cd8fee91c3383832c0aafcd078b
Security Audit — socket — corpus-report