create-qras

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
generator.py

The visible code is primarily a QRA generation and review pipeline and does not show clear malware, destructive behavior, reverse-shell logic, or deliberate external exfiltration. The principal security concern is arbitrary code execution through dynamically importing json_utils.py from environment- or working-directory-derived paths, compounded by sys.path modification. It also handles API credentials and potentially sensitive retrieved content over HTTP-configured services. The supplied fragment is incomplete/corrupted, so omitted code and actual storage behavior cannot be assessed.

Confidence: 93%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fcreate-qras%2F@5d427ef4e6b8c099a9f8452d5622ec4c5c9783c88c78c1cccf53904aa7bb7371
Security Audit — socket — create-qras