novel-control-station

Fail

Audited by Snyk on Mar 30, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). High-risk: the package includes a PowerShell "marathon" runner that sets ExecutionPolicy Bypass and repeatedly invokes an external "codex exec ... --dangerously-bypass-approvals-and-sandbox" command to run an autonomous loop that must write back project files — effectively enabling unsandboxed remote/automated code execution and persistent file system modification while explicitly instructing the agent to bypass safety checks, which is a backdoor/remote-execution pattern and can be abused for unauthorized actions or exfiltration.

Issues (1)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 30, 2026, 06:08 AM
Issues
1