data-scientist

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
references/subagent-experiment-supervision.md

No clear evidence of direct malware/backdoors is present in the shown fragment. The dominant security finding is a high-impact supply-chain risk: the supervisor can automatically run pip install for a package name extracted from untrusted log text, without allowlisting, pinning, or provenance checks. This could enable typosquatting/dependency confusion or attacker-driven sabotage if logs/errors can be influenced. A secondary concern is potential leakage via escalation/Telegram messaging that may include log-derived snippets. Hardening should focus on disabling or strictly controlling auto-install (e.g., disable by default; allowlist/pin approved packages; require human approval) and minimizing sensitive data in notifications.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Sep 2, 2026, 05:57 PM
Package URL
pkg:socket/skills-sh/magnus919%2Fagent-skills%2Fdata-scientist%2F@c0bf329384cd14fa268823338a8ff3db97eccfac0396789436fbbe95cce77cb2
Security Audit — socket — data-scientist