story-lab

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
sanity.sh

This is a project sanity-check script with legitimate testing behavior and no clear malicious payload, credential theft, exfiltration, persistence, or system damage. However, its use of eval with dynamically interpolated paths and especially captured CLI output creates a command-injection risk and should be replaced with direct command execution or safely quoted arguments. The fragment alone provides insufficient evidence of malware, but the executed converge.py and uv dependencies require separate review.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fstory-lab%2F@a045c4bb27c421799a149370c344968831f44d39dd51e6afd94001f787e3b034
Security Audit — socket — story-lab