review-assurance-case
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalyproviders/registry.py
LOWAnomalyLOW
providers/registry.py
The code is an AI-provider CLI orchestration layer, not evident malware. It safely avoids shell-based command injection by using create_subprocess_exec with argument lists, but it intentionally launches external tools with highly permissive capabilities and passes them the full process environment. The main security concern is excessive delegated authority and possible exposure of environment secrets to the configured provider CLI. The dynamically modified import path is also a supply-chain concern if the skills directory is writable or untrusted. No direct exfiltration, persistence, credential theft, or destructive behavior is visible in the supplied fragment.
Confidence: 94%Severity: 58%
Audit Metadata