sverchok-syntax-scripting

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Anomaly
AnomalyLOW
references/methods.md

No explicit malicious behavior is present in the provided text, but the documentation describes an exec()-based dynamic script loading/execution path and broad injection of high-privilege objects (notably bpy) into the script/formula evaluation environment. In a supply-chain scenario (malicious/poisoned scripts or templates), this would enable arbitrary code execution within the Blender process. The static analysis signal is likely tied to these execution mechanisms rather than visible malware in this snippet.

Confidence: 62%Severity: 65%
Audit Metadata
Analyzed At
Jul 23, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/impertio-studio%2Fblender-bonsai-ifcopenshell-sverchok-claude-skill-package%2Fsverchok-syntax-scripting%2F@45a9f7bcb8f8eab3b7fc1ce52bf6af902d23d841ef6b18bb2edb829aff4eedec
Security Audit — socket — sverchok-syntax-scripting