test-interactions

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
test_interactions.py

The code is primarily a browser UI testing and visual-review CLI, and the supplied fragment contains no clear malware, persistence, destructive behavior, reverse shell, or broad system-data exfiltration. The main security concerns are the hardcoded bearer token, transmission of screenshots and test evidence to a local AI proxy, execution of delegated shell scripts, and possible JavaScript injection through the unvalidated scroll amount. Validate numeric manifest fields before interpolation, remove the embedded token in favor of secure configuration, constrain delegated scripts, and treat captured screenshots as sensitive data.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:03 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Ftest-interactions%2F@4bcad8d70ea95314cfa76c8b7e2410031232777e786d3961376af58ec4301fa9
Security Audit — socket — test-interactions