story-lab
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalysanity.sh
LOWAnomalyLOW
sanity.sh
This is a project sanity-check script with legitimate testing behavior and no clear malicious payload, credential theft, exfiltration, persistence, or system damage. However, its use of eval with dynamically interpolated paths and especially captured CLI output creates a command-injection risk and should be replaced with direct command execution or safely quoted arguments. The fragment alone provides insufficient evidence of malware, but the executed converge.py and uv dependencies require separate review.
Confidence: 98%Severity: 58%
Audit Metadata