ops-streamdeck

Warn

Audited by Socket on Mar 17, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
run.sh

This script is not obfuscated and contains legitimate service-management and configuration functionality for a Stream Deck skill. However it contains a high-risk pattern: it reads command strings from a user-writable JSON config (~/.streamdeck_ui.json) and executes them with eval without validation or sanitization. That creates an easy local arbitrary code execution vector if an attacker can modify the config file or if the config comes from an untrusted source. The rest of the script (systemctl calls, file writes) are powerful administrative actions but expected for its purpose. Recommendation: avoid using eval; instead execute commands more safely (e.g., restrict allowed commands, run via a whitelist, or use execve with args parsed safely), validate ownership/permissions of config files, and avoid trusting backups without integrity checks.

Confidence: 90%Severity: 66%
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s local Stream Deck control purpose generally matches its capabilities, but the trust model is weakened by direct execution from an unverified GitHub repo and by broad command execution through button mappings. Data flow is mostly local and not overtly exfiltrative, so this is not confirmed malware, but it carries meaningful supply-chain and host-action risk.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:44 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fops-streamdeck%2F@e135c0e406bee50fbf856f36a965ef28c1bdf83c
Security Audit — socket — ops-streamdeck