ticket

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/ticket_cli.py

The code is a GitHub ticket and CI lifecycle CLI. It does not show evidence of malware, data theft, persistence, or covert network activity. Its intended subprocess and GitHub operations are consistent with its stated purpose. However, verify() provides direct arbitrary shell execution through untrusted --cmd strings, and the external GH_HELPER script is an important unreviewed execution dependency. The supplied fragment also contains syntax errors that likely prevent execution. Use only with trusted local users and review the helper script separately; avoid exposing verify() to untrusted input.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fticket%2F@69dbfc0e5d3f80e1526dcf9d65729017acf39e8cbd0a97d4f4a31afcd9657260
Security Audit — socket — ticket