debugger

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
fixtures/ownership-persistence.json

The fragment defines a legitimate but explicitly destructive debugger durability test. Its primary security concern is broad process termination of matching Node service processes, which can disrupt VS Code or other processes if the pattern matches unexpectedly. Environment-controlled paths and the unquoted runtime-directory glob create limited robustness and command/path-handling concerns. There is no clear evidence of malware, data theft, or supply-chain backdoor behavior in this fragment.

Confidence: 97%Severity: 62%
SecurityMEDIUM
scenarios/secret_capture/leaky.py

The code does not show evidence of malware, exfiltration, or a backdoor. It contains exposed credential-like hardcoded values and a broken authentication implementation that returns True for any non-empty user. The syntax error also prevents execution as written. The hardcoded values should be removed and rotated, and authentication should verify credentials using a secure mechanism.

Confidence: 99%Severity: 78%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:06 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fdebugger%2F@f9c3ab5395169511ea1d61a678641f5dc6feba6fa7958bf897e872e90bc98868
Security Audit — socket — debugger