loki-mode
Audited by Socket on Jul 28, 2026
3 alerts found:
Securityx3SUSPICIOUS. The skill’s footprint is coherent with autonomous orchestration, but that stated purpose is itself excessively broad and paired with mandatory permission bypass and no-confirmation behavior. Install provenance is mostly official, yet the combination of unrestricted execution, deployment/business-action scope, and autonomous operation makes this a high-risk skill rather than benign documentation.
Moderate-to-high supply-chain risk. The script is an autonomous runner that repeatedly executes Claude Code with `--dangerously-skip-permissions`, which strongly increases the impact of any compromised/malicious agent behavior, prompt injection in PRD/docs/ledger context, or manipulated local state. It also serves a local dashboard that renders unescaped JSON into `innerHTML`, enabling DOM XSS if queue/agent data is attacker-controlled. No direct credential theft or network exfiltration is evident in the provided fragment, but the autonomy/policy bypass combination warrants thorough review and sandboxing/permission hardening.
This code is highly unsafe because it builds a Python expression string from caller-controlled `operator` and `operand` values and passes it directly to `eval()`. Without strict allowlisting of operators and strict numeric validation of operands, it enables arbitrary code execution (RCE) in the Python process. Treat as critical security risk and avoid using in any context where inputs can be influenced by an attacker.