letta-api-client

Fail

Audited by Socket on Apr 23, 2026

1 alert found:

Malware
MalwareHIGH
examples/typescript/13_client_side_tools.ts

High-risk capability. This module enables arbitrary shell command execution on the local host driven by untrusted agent/tool-call arguments, using execSync with no sanitization/allowlisting or real local policy enforcement. It also returns stdout/stderr back to the remote agent service and logs outputs, creating both remote command execution and local data exposure/exfiltration risk. Suitable only for tightly controlled, trusted environments with strong upstream validation and strict human/system approval outside this code.

Confidence: 78%Severity: 100%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:39 AM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fletta-api-client%2F@577182607a30c3a8332f6ecd247c056165ef029f