ingest-doc
Audited by Socket on Mar 17, 2026
2 alerts found:
AnomalySecurityThis Python module itself contains no obvious direct malware (no network exfiltration, no eval/obfuscation, no hard-coded secrets). However, it intentionally executes external shell scripts and conditionally imports a module from ~/.pi/skills, which creates a significant supply-chain and local code execution risk: a malicious or tampered skill script or a compromised ~/.pi/skills TaskClient can perform arbitrary harmful actions when this CLI runs. Treat the skill scripts and the ~/.pi/skills import path as untrusted inputs; verify their integrity and ownership before using this package in sensitive environments.
SUSPICIOUS. The stated purpose is coherent for a document-ingestion orchestrator, and permissions are not wildly disproportionate, but the core execution path is unverifiable: ./run.sh and six composed skills are trusted without provenance, versioning, or release details. URL ingestion and ArangoDB storage are also underdocumented, leaving data-flow and transitive-trust gaps. No direct credential theft or clearly malicious endpoint is shown, so this is not confirmed malware, but it carries medium-high supply-chain and orchestration risk.