autonomous-loop-safety

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/notify.sh

The code is a straightforward macOS automation script that reads arbitrary text from local outbox files and transmits it externally via iMessage to a hardcoded recipient, then clears the outbox. This creates an explicit outbound data channel consistent with exfiltration behavior in a supply-chain context. Additionally, it writes the full message body to a local log on failure, increasing the chance of sensitive data disclosure. While there is no classic malware behavior (no persistence, downloading, or reverse shell), the intended function is risky and should be treated as potentially malicious depending on how the outbox files are populated.

Confidence: 70%Severity: 78%
Audit Metadata
Analyzed At
Jul 14, 2026, 11:28 PM
Package URL
pkg:socket/skills-sh/jeremyinthebay%2Frelay-skills%2Fautonomous-loop-safety%2F@5c68956dd0bca38aa812dfa1b9fc733d1b997fe675a7f0f60f2f368392ed341e
Security Audit — socket — autonomous-loop-safety