model-selector

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/grade.py

The fragment appears to be a legitimate local grading pipeline, not malware. It contains no clear credential theft, network exfiltration, destructive behavior, or obfuscated payload. However, it deliberately executes a command supplied by the bridge subprocess without executable allowlisting, so compromise of selection.py, its configuration, or its output can result in arbitrary local command execution. Review the bridge trust model and protect pending data and configuration files.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 07:35 AM
Package URL
pkg:socket/skills-sh/kntnt%2Fskills%2Fmodel-selector%2F@ce24e1d50c0293e236e17bc19fca6ddbb9f01e7e240ebb65abe3873ba31727ca
Security Audit — socket — model-selector