devenv

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
envrc

The code is a thin local environment initializer, but it uses `eval` to execute runtime output from `devenv direnvrc` without sanitization. This creates a direct arbitrary-command-execution path in the current shell if the generated content is compromised or attacker-influenced. No overt malicious payloads (exfiltration, persistence, credentials) are visible in the snippet itself, but the wrapper’s execution model makes supply-chain/config compromise high-impact.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
May 10, 2026, 05:47 PM
Package URL
pkg:socket/skills-sh/kissgyorgy%2Fcoding-agents%2Fdevenv%2F@01a8aca18a4ff8ed215b2e97e366baafda864ef1
Security Audit — socket — devenv