aep-executor
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalyreferences/claude-native.md
LOWAnomalyLOW
references/claude-native.md
No concrete evidence of intentional malware (e.g., exfiltration, backdoor behaviors, credential harvesting) is present in the provided fragment. However, the design contains multiple high-impact control-plane risk factors: execution of a worktree-local recovery script (`bash .dev-workflow/init.sh`), use of `--dangerously-skip-permissions` for detached background sessions, and insertion of free-form human text into prompts that drive autonomous continuation. Treat this as moderate security risk pending review of the actual orchestrator implementation and the safety/integrity of the recovery script and state handling.
Confidence: 46%Severity: 54%
Audit Metadata