letta-api-client
Fail
Audited by Socket on Apr 23, 2026
1 alert found:
MalwareMalwareexamples/typescript/13_client_side_tools.ts
HIGHMalwareHIGH
examples/typescript/13_client_side_tools.ts
High-risk capability. This module enables arbitrary shell command execution on the local host driven by untrusted agent/tool-call arguments, using execSync with no sanitization/allowlisting or real local policy enforcement. It also returns stdout/stderr back to the remote agent service and logs outputs, creating both remote command execution and local data exposure/exfiltration risk. Suitable only for tightly controlled, trusted environments with strong upstream validation and strict human/system approval outside this code.
Confidence: 78%Severity: 100%
Audit Metadata