pwf-enforcer

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/pwf-enforcer.ts

This module is mainly a workflow enforcement plugin, but it carries significant security exposure due to execSync-based execution of local shell scripts (inject-plan.sh/check-complete.sh). Critically, the directory containing those scripts can be overridden directly via process.env.PWF_DIR without validation, making the overall risk highly dependent on how trusted that environment variable and the on-disk scripts are. In the absence of attacker influence over PWF_DIR or the scripts directory, the malware/exfiltration likelihood is low; however, the potential for host-level arbitrary command execution is non-trivial and should be treated as a supply-chain/runtime trust boundary issue.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
Jul 21, 2026, 02:38 PM
Package URL
pkg:socket/skills-sh/meisijiya%2Fskills%2Fpwf-enforcer%2F@d7f8c4d8d8a6c7aa0f0482d6f814537e8c3456dab5df3c527cc3f55e4fea6f9c
Security Audit — socket — pwf-enforcer