matrix-communication

Warn

Audited by Socket on Sep 18, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/matrix-send-e2ee.py

The visible code is a Matrix messaging client and does not contain clear malware or unauthorized data exfiltration. It performs expected credential use and Matrix network operations. However, it weakens end-to-end encryption authentication by automatically trusting unverified devices and explicitly ignoring verification status. The local sys.path modification and opaque helper imports warrant review of adjacent files, especially _lib.py, but are not sufficient evidence of malicious behavior in this fragment.

Confidence: 93%Severity: 58%
AnomalyLOW
scripts/_lib/formatting.py

The fragment is a readable Markdown and Matrix formatting utility with no evident malicious behavior or external side effects. Its main security concern is unsafe HTML generation: caller-controlled Markdown and link values are inserted into HTML without escaping or URL-scheme validation. This can cause HTML injection or XSS when the returned HTML is rendered in a browser or other HTML-capable client. The issue is contextual and is not evidence of supply-chain malware.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:09 AM
Package URL
pkg:socket/skills-sh/netresearch%2Fmatrix-skill%2Fmatrix-communication%2F@8dcdfe3e7a64ae41e626bd3625841d661a73adac159b222b305b3030f39bf197