lokf-scaffolding
Warn
Audited by Socket on Sep 11, 2026
1 alert found:
AnomalyAnomalytemplates/scripts/knowledge-librarian.sh
LOWAnomalyLOW
templates/scripts/knowledge-librarian.sh
The fragment is not itself malware and contains no direct exfiltration, persistence, sabotage, or credential harvesting. Its main risk is deliberate execution of an arbitrary AGENT_CLI value with repository access; the prompt-only restriction on the external agent is not a security control. The configuration source and agent implementation should therefore be trusted and constrained by the workflow runtime, permissions, and environment. The unquoted expansion also introduces shell parsing risks if AGENT_CLI is attacker-controlled or unexpectedly formatted.
Confidence: 97%Severity: 62%
Audit Metadata