model-selector
Warn
Audited by Socket on Sep 20, 2026
1 alert found:
AnomalyAnomalyscripts/grade.py
LOWAnomalyLOW
scripts/grade.py
The fragment appears to be a legitimate local grading pipeline, not malware. It contains no clear credential theft, network exfiltration, destructive behavior, or obfuscated payload. However, it deliberately executes a command supplied by the bridge subprocess without executable allowlisting, so compromise of selection.py, its configuration, or its output can result in arbitrary local command execution. Review the bridge trust model and protect pending data and configuration files.
Confidence: 94%Severity: 58%
Audit Metadata