schedule

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/schedule.mjs

No clear evidence of overt supply-chain malware, obfuscation, network exfiltration, or credential theft in this fragment. However, the package is inherently high-risk from a threat-model perspective because it can execute external binaries (codexBin/resumeCommand) and can inject prompts into tmux sessions, with task.prompt/task.cwd sourced from CLI and persisted tasks.json. If an attacker can influence CLI arguments or stateRoot/tasks.json, this becomes a powerful local code-execution/interactive-injection vector. If stateRoot and inputs are trusted, the security risk is lower.

Confidence: 75%Severity: 65%
Audit Metadata
Analyzed At
Aug 11, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/mineru98%2Fskills-store%2Fschedule%2F@02a3fc35f040fda29ba835a5bd8b7f409e5251938ce0bbe972e4fb884a39f08a
Security Audit — socket — schedule