ai-engineering

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
evals/files/askdesk/extract_refund.py

No clear malware or intentional sabotage is present in the visible code. However, the design creates a significant security risk by allowing untrusted ticket content and unconstrained model output to trigger refunds without independent validation or authorization. The fragment is also syntactically incomplete because PROMPT has no value and the refund call is truncated.

Confidence: 96%Severity: 78%
SecurityMEDIUM
evals/files/askdesk/agent_loop.py

The fragment does not show clear intentional malware or obfuscation, but it contains a high-impact agent design risk: untrusted ticket content can influence an LLM that is permitted to execute refunds, send emails, read tickets, and escalate cases without local authorization, validation, or confirmation. The code also has syntax errors and lacks an independent tool allowlist and policy enforcement. Underlying askdesk.tools implementations would require review to determine the actual impact.

Confidence: 98%Severity: 84%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fai-engineering%2F@4d11fe603cfd3651504f96b35446e4f4edd6537449dfed1460e77f0b892700e0
Security Audit — socket — ai-engineering