loop

Warn

Audited by Socket on Aug 26, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/loop.py

The code implements a legitimate but high-privilege automation harness. It intentionally executes arbitrary configured shell commands and repository-modifying agents, so agent configuration, check arguments, and environment must be trusted. The main security concerns are shell execution, propagation of inherited environment secrets, and an unrestricted absolute --run-root. No direct malware or covert exfiltration behavior is evident. The provided fragment also appears syntactically incomplete at its final SystemExit call.

Confidence: 98%Severity: 62%
AnomalyLOW
scripts/loop_cron_runner.sh

The code is a shell-based scheduled automation runner, not intrinsically malware. Its main security risk is deliberate arbitrary command execution through bash -lc and the configurable LOOP_CODEX_CMD, combined with an unvalidated prompt file. Manifest JSON construction is unsafe for untrusted metadata but does not itself execute code. No direct data theft, persistence, suspicious network activity, or destructive behavior is shown.

Confidence: 97%Severity: 64%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Floop%2F@691d43fe0e07a444d2e1d62f2a069fbbb74a87f533d6fb5ae16a3b5d9f025264
Security Audit — socket — loop