lokf-scaffolding

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/scripts/knowledge-librarian.sh

The fragment is not itself malware and contains no direct exfiltration, persistence, sabotage, or credential harvesting. Its main risk is deliberate execution of an arbitrary AGENT_CLI value with repository access; the prompt-only restriction on the external agent is not a security control. The configuration source and agent implementation should therefore be trusted and constrained by the workflow runtime, permissions, and environment. The unquoted expansion also introduces shell parsing risks if AGENT_CLI is attacker-controlled or unexpectedly formatted.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 11, 2026, 09:27 PM
Package URL
pkg:socket/skills-sh/noelmcloughlin%2Flokf-agent-skills%2Flokf-scaffolding%2F@fd4175160613ee238bd9ca6d7ecfd37cba04ffe1b1e7454fb33d21845f5ab945
Security Audit — socket — lokf-scaffolding