sparta-review
Audited by Socket on Mar 17, 2026
2 alerts found:
AnomalyObfuscated FileSUSPICIOUS: the stated review purpose is mostly coherent, but the skill expands into autonomous looping, destructive auto-fix behavior, and external research over untrusted content with Bash/Write access. Main risks are autonomy and prompt-injection exposure, plus underdocumented credential/data flows for CHUTES-backed research rather than confirmed malware.
This file implements a local reviewer utility around DuckDB but is syntactically broken and incomplete as provided. I found no direct evidence of remote data exfiltration, reverse shells, or intentional obfuscation/malicious payloads. The main security concerns are: predictable snapshot files in /tmp (information disclosure and symlink/race risks), unsafe SQL string interpolation of reviewed IDs (possible SQL injection if inputs are not validated), and broad exception swallowing that can mask failures. Before use, the code must be repaired (restore missing SQL and function calls), harden snapshot handling (use secure temp files or unique, permission-restricted locations), and parameterize SQL queries to avoid string injection. Treat the fragment as non-functional and potentially risky to run unchanged; review the full original source for tampering if this corruption was unexpected.