sfx-catalog

Fail

Audited by Socket on Mar 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
sfx-catalog/src/memory_bridge.py

The Python fragment is a thin wrapper that delegates all substantive work to a local memory/run.sh script. The code itself contains no obvious direct malicious payloads (no eval, network libs, or hardcoded credentials), but it creates a supply-chain/local-file risk: if the resolved run.sh is malicious or tampered with, arbitrary code execution and data exfiltration are possible. Additional concerns: arguments include serialized JSON (potentially large or sensitive) passed on the command line (visible to other local users), and the snippet is truncated which limits full verification. Recommend verifying the provenance and contents of memory/run.sh, avoid passing sensitive data on the command line (use stdin or secure IPC), validate JSON returned by the external process, and avoid brittle multi-parent path resolution.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 17, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fsfx-catalog%2F@86af85affe4f4e6ccf34b12d1abf811c0f791dbd
Security Audit — socket — sfx-catalog