personaplex
Audited by Socket on Aug 26, 2026
5 alerts found:
Securityx2Anomalyx3The code appears to implement an intentionally designed local voice/research service and contains no clear malware such as persistence, theft, destructive actions, or cryptomining. It does contain a significant command-injection risk because user-controlled brave_query is interpolated into bash -lc, and an arbitrary filesystem-write risk through output_dir. The Brave invocation should avoid a shell entirely and pass arguments directly; output paths and endpoint access should also be constrained and authenticated.
The fragment appears to be a local PersonaPlex GPU validation and receipt-generation harness, with no clear evidence of intentional malware, data theft, persistence, or covert network exfiltration. Security risks include arbitrary local subprocess execution when paths or environment variables are attacker-controlled, unconstrained receipt paths that can overwrite writable files, and disabled WebSocket TLS certificate verification. The displayed fragment is also syntactically incomplete and contains a likely definition-order bug around the __main__ block.
The code appears to be a local integration/probing script rather than malware. It has a high-impact command-injection vulnerability in run_brave() because untrusted --brave-query data is embedded in a bash -lc command. It also disables TLS verification for the WebSocket connection and permits a user-selected remote endpoint, allowing prompt and audio interception or redirection. Replace shell execution with a direct subprocess argument list, avoid sourcing shell startup files, validate the WebSocket endpoint, and enable certificate verification.
The code appears to be a legitimate offline Personaplex/Moshi audio-generation harness. No clear malicious behavior or data exfiltration is present. The significant security risk is unrestricted torch.load() deserialization of the voice-prompt file, which can permit arbitrary code execution if that file is attacker-controlled or tampered with. Use a trusted file and a restricted loading mode such as weights_only=True where compatible, or validate the artifact before deserialization. The supplied fragment also appears syntactically truncated at the final `rais` token.
The fragment appears to be a test/compliance fixture runner, not malware. The main security risk is unsafe recursive deletion of the caller-selected --run-root path, which could destroy arbitrary files if the tool is run with an incorrect or attacker-controlled path. The behavior of the imported harness remains unassessed. No credential theft, exfiltration, reverse shell, persistence, cryptomining, or code injection is visible in this file.