status

Warn

Audited by Socket on May 12, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
_shared/communication/message-queue.js
AnomalyLOW
_shared/communication/README.md

No explicit malware is present in the provided snippet (it contains configuration and documentation only). However, it defines a hook-based system that executes arbitrary shell commands from a user-writable hooks directory and persists extensive event/task/tool activity into local JSONL logs. If hook scripts or the hook configuration are compromised, this architecture could enable persistence, data theft, or other impact; additionally, verbose logging increases the chance of sensitive data exposure at rest unless redaction/retention controls are implemented in the unseen hook/logging scripts. Review the referenced hook scripts and the workflow-init/message-queue implementations for command safety, redaction, and integrity protections.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 04:10 AM
Package URL
pkg:socket/skills-sh/miles990%2Fmulti-agent-workflow%2Fstatus%2F@c8578962bbce64f07359452ecaa2272b0dcf2625