effect-ts

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
references/processes.md

The fragment is process and scope management documentation with legitimate child-process examples. It contains no evidence of embedded malware, exfiltration, credential theft, or sabotage. However, both runWithInput and startBackground execute caller-provided strings through bash -c, which is a high-impact command-injection/arbitrary-command-execution risk when command values can be influenced by untrusted input. The daemon and manually managed scope patterns also require reliable cleanup to prevent lingering processes and resource leaks.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:22 AM
Package URL
pkg:socket/skills-sh/joelhooks%2Feffectts-skills%2Feffect-ts%2F@a12b88bceef4524303b736ea1017db63f1c4f37345b170d2a1ac206ea5656802
Security Audit — socket — effect-ts