ingest-code

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
ingest_code.py

No clear, intentional malware (reverse shell, cryptominer, hardcoded malicious domain) was found in this file. However, the code performs large-scale reading of repository files and will send extracted text and CWE findings to a configurable memory service (HTTP POST) or execute local 'memory' scripts. This design creates a realistic supply-chain/data-exfiltration risk if MEMORY_SERVICE_URL or local skill scripts are attacker-controlled. The auto-pip install on import and dynamic imports from home directories are additional risky behaviors. Use only with trusted memory backends and trusted local skill modules.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:40 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fingest-code%2F@60765111e67ef1d935b8942b7ae4f8c7707ba534
Security Audit — socket — ingest-code