novel-control-station
Fail
Audited by Snyk on Mar 30, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). High-risk: the package includes a PowerShell "marathon" runner that sets ExecutionPolicy Bypass and repeatedly invokes an external "codex exec ... --dangerously-bypass-approvals-and-sandbox" command to run an autonomous loop that must write back project files — effectively enabling unsandboxed remote/automated code execution and persistent file system modification while explicitly instructing the agent to bypass safety checks, which is a backdoor/remote-execution pattern and can be abused for unauthorized actions or exfiltration.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata