copyparty

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/features-upload-media.md

No direct evidence of embedded malware is present in the provided excerpt (it is descriptive documentation rather than executable malicious logic). The primary security concern is the explicitly documented ability to execute external hook/plugin scripts/commands and to perform destructive/relocating file actions as part of upload/media lifecycle events. If an attacker can tamper with hook/plugin configuration or script paths, this mechanism could enable arbitrary code execution and potentially exfiltration/logic abuse via the executed code. Network contact shown here is mainly version-checking and optional messaging integration, without clear malicious destinations.

Confidence: 55%Severity: 62%
Audit Metadata
Analyzed At
Jun 18, 2026, 05:20 PM
Package URL
pkg:socket/skills-sh/kettleofketchup%2Fdotfiles%2Fcopyparty%2F@bde55fd23a166146cd290a15df43eea1229ee4b43543d3816a86c2708cb24927
Security Audit — socket — copyparty