map-features

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/overlay.py

The fragment appears to implement a local findings-overlay indexer, not malware. It has a potentially significant arbitrary-file-write/path-traversal issue because observation_id controls a filesystem path without validation. Risk depends on whether env findings can be influenced by an attacker; the code alone does not show such influence. No network, credential theft, command execution, or destructive behavior is present.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 5, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/jayden-dang%2Fskills%2Fmap-features%2F@542167cb66ffcd85ad4d5219c7498e3e4a71455915d37c82543364b0e220247d
Security Audit — socket — map-features