thunderdome
Audited by Socket on Aug 26, 2026
3 alerts found:
Securityx2AnomalySUSPICIOUS. The stated purpose is coherent for orchestration, but the skill expands trust to an unseen local runner and multiple internal composed skills/services without provenance or pinning, and it creates a high-risk indirect prompt-injection loop by recycling untrusted subagent/research outputs while Bash and Write are available. No clear malware or explicit credential theft is present in the provided text.
The code is a benchmark dispatcher with legitimate subprocess execution, not clear malware. However, it constructs shell commands through unescaped string interpolation and executes them with bash, creating a meaningful command-injection risk if strategy configuration or data_dir is attacker-controlled. Use subprocess argument arrays, strict validation, and safe temporary paths instead of bash string interpolation. No direct data theft or malicious payload is evident in this fragment.
The code appears intended for dataset inspection, local research execution, and strategy selection. It does not show clear malicious behavior, but dogpile_research contains a high-impact command-injection vulnerability because the query is embedded unescaped in a bash -lc command. Use subprocess.run with a direct argument list and avoid invoking a shell. Assessment is limited because the fragment is truncated.