create-persona
Audited by Socket on Aug 26, 2026
2 alerts found:
Obfuscated Filex2This module itself does not contain clearly malicious code (no obfuscation, no eval/exec, no embedded credential harvesting or network exfiltration). The primary security concern is that it executes external artifacts (user-local memory-agent binary or discovered run.sh skill scripts) from predictable filesystem locations without provenance checks. That design creates a supply-chain and local trust vulnerability: a compromised or attacker-placed binary/script can achieve arbitrary code execution with the running process's privileges and can produce malicious JSON to poison application state. Additionally, there is a functional bug in get_colleagues (returns undefined variable) that will cause a runtime exception. Recommendations: 1) Avoid executing scripts from writable/untrusted locations; require signed artifacts or a strict allowlist; 2) Validate and/or schema-check JSON returned from external tools; 3) Consider sandboxing or running external tools with restricted privileges; 4) Fix the get_colleagues return bug; 5) Treat ~/.local/bin/memory-agent as untrusted and ensure installation/update processes protect its integrity.
The inspected module is a helper layer for persona and voice-reference management that is not obviously malicious by itself: no eval/exec, no hard-coded secrets, and code is readable. The primary security concern is that it delegates network/subprocess work to run_skill and external 'skills' (ingest-youtube, dogpile, discover-*). Those external components can perform network access and arbitrary execution; their behavior determines the real security posture. Additionally, two coding errors (undefined logger usage and 'return Non') will cause runtime exceptions. Recommend auditing run_skill and the external skills, validating and sanitizing any untrusted inputs passed to them, and fixing the noted bugs before production use.