ops-streamdeck
Audited by Socket on Mar 17, 2026
2 alerts found:
AnomalySecurityThis script is not obfuscated and contains legitimate service-management and configuration functionality for a Stream Deck skill. However it contains a high-risk pattern: it reads command strings from a user-writable JSON config (~/.streamdeck_ui.json) and executes them with eval without validation or sanitization. That creates an easy local arbitrary code execution vector if an attacker can modify the config file or if the config comes from an untrusted source. The rest of the script (systemctl calls, file writes) are powerful administrative actions but expected for its purpose. Recommendation: avoid using eval; instead execute commands more safely (e.g., restrict allowed commands, run via a whitelist, or use execve with args parsed safely), validate ownership/permissions of config files, and avoid trusting backups without integrity checks.
SUSPICIOUS: The skill’s local Stream Deck control purpose generally matches its capabilities, but the trust model is weakened by direct execution from an unverified GitHub repo and by broad command execution through button mappings. Data flow is mostly local and not overtly exfiltrative, so this is not confirmed malware, but it carries meaningful supply-chain and host-action risk.