autogen

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/code-execution.py

This module itself contains no obvious malicious code, secrets, or direct data-stealing logic. However, it implements a fully automated pipeline where untrusted LLM output is used to drive code execution inside a Docker executor (human_input_mode="NEVER"), creating a meaningful security risk. The true risk level depends on the Docker executor’s sandboxing (network/file/privilege restrictions) and any policy enforcement in the wider codebase, which are not shown here.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Sep 2, 2026, 05:56 PM
Package URL
pkg:socket/skills-sh/magnus919%2Fagent-skills%2Fautogen%2F@9b8b978d216d46f4234f4b62749c58cc78545a43c0199d07c574638fe522543c
Security Audit — socket — autogen