schedule
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
AnomalyAnomalyscripts/schedule.mjs
LOWAnomalyLOW
scripts/schedule.mjs
No clear evidence of overt supply-chain malware, obfuscation, network exfiltration, or credential theft in this fragment. However, the package is inherently high-risk from a threat-model perspective because it can execute external binaries (codexBin/resumeCommand) and can inject prompts into tmux sessions, with task.prompt/task.cwd sourced from CLI and persisted tasks.json. If an attacker can influence CLI arguments or stateRoot/tasks.json, this becomes a powerful local code-execution/interactive-injection vector. If stateRoot and inputs are trusted, the security risk is lower.
Confidence: 75%Severity: 65%
Audit Metadata