task-monitor

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Security
SecurityMEDIUM
task_monitor/http_api.py

The code implements a plausible task-monitoring API and does not show clear malware or obfuscation. However, it contains a high-impact command-execution sink: task.on_complete is executed with shell=True, and output_dir is interpolated without shell escaping. It also writes to a caller-influenced state_file path and exposes administrative operations without visible authentication. These issues could enable arbitrary command execution or filesystem writes if task registration is reachable by an untrusted user or if validation is incomplete. Review and constrain hook commands, avoid shell=True, validate paths against an allowed root, and enforce authentication and authorization.

Confidence: 94%Severity: 84%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftask-monitor%2F@e048e8d4c1f545b9c5f6136181ee7e1c9d8c51b7
Security Audit — socket — task-monitor