data-scientist

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
references/subagent-experiment-supervision.md

No clear evidence of direct malware/backdoors is present in the shown fragment. The dominant security finding is a high-impact supply-chain risk: the supervisor can automatically run pip install for a package name extracted from untrusted log text, without allowlisting, pinning, or provenance checks. This could enable typosquatting/dependency confusion or attacker-driven sabotage if logs/errors can be influenced. A secondary concern is potential leakage via escalation/Telegram messaging that may include log-derived snippets. Hardening should focus on disabling or strictly controlling auto-install (e.g., disable by default; allowlist/pin approved packages; require human approval) and minimizing sensitive data in notifications.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Aug 12, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/magnus919%2Fhermes-profiles%2Fdata-scientist%2F@5c52a2f2d9bdfbe36bd05568e3b36b6c629eb0a74ac061edc91c3cef5c78c5d3
Security Audit — socket — data-scientist