build

Warn

Audited by Socket on Sep 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/peer-build.mjs

No explicit malicious payloads, credential theft, obfuscation, or direct network exfiltration are evident in this snippet. However, the module is a high-privilege orchestrator: it writes plan-derived prompts to disk and executes an externally constructed command (via runBounded with stdin=prompt and cwd=user-controlled worktree). Because buildInvocation/checkAuth/runBounded implementations are not shown, the primary supply-chain risk is that unsafe command/argument construction or insufficient sandboxing could allow command abuse or unintended side effects. Overall risk is moderate, focused on execution/sandboxing rather than clear malware behavior in this fragment.

Confidence: 48%Severity: 56%
Audit Metadata
Analyzed At
Sep 10, 2026, 06:03 AM
Package URL
pkg:socket/skills-sh/maxgfr%2Fskills%2Fbuild%2F@c8a4ef6618bfdf8ecb9906c05b1012f16d85833ede296c154b6b9d63f30b0a14
Security Audit — socket — build