ops-nzbgeek

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
ops_nzbgeek/interview_helper.py

The Python code itself contains no direct malicious logic (no hardcoded secrets, no eval/exec, no network calls). However, it executes an external shell script located at ~/.pi/skills/interview/run.sh and fully trusts that script's output (parsing stdout as JSON). That makes this module a supply-chain/execution-risk vector: if the run.sh is malicious or replaced, an attacker can control program flow, provide arbitrary JSON, or read the session file. Therefore the code is low-risk by itself but exposes substantial risk due to executing and trusting an unverified external script. Recommend validating or signing run.sh, restricting its location/permissions, validating the JSON output before use, and avoiding running untrusted local scripts.

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:41 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fops-nzbgeek%2F@1d3ca5557f3075fa6e8499d6e2a9435ac7fc7f87
Security Audit — socket — ops-nzbgeek