im-up

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Security
SecurityMEDIUM
validate_packet.py

This module is not obviously malware by itself (no networking, persistence, or explicit theft code), but it contains an intentionally powerful and security-sensitive mechanism: it executes shell commands (shell=True) supplied by external JSON configuration and can also execute packet-derived “verified” command probes when they match a config-derived allowlist. If attackers can influence the packet or especially the config/allowlist content (common in supply-chain/CI contexts), this becomes a practical RCE and local information disclosure risk via captured command stdout/stderr included in the JSON receipt. Secret/placeholder scanning is present but does not mitigate the command execution threat.

Confidence: 78%Severity: 78%
Audit Metadata
Analyzed At
Aug 31, 2026, 09:18 PM
Package URL
pkg:socket/skills-sh/mrbinnacle%2Fskills%2Fim-up%2F@cca55159d8846220f1dc609a600aa6498755fd6254f1b7545b81c8ebe1f157ec
Security Audit — socket — im-up