nv-segment-ctmr

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
BENCHMARK.md

This fragment provides no direct skill source code, but it reports a meaningful static finding around process execution (`subprocess.run` with `cmd` and a custom environment) and broader Bash/least-privilege concerns (environment manipulation and file I/O). The fragment contains no explicit evidence of malware behaviors like data exfiltration or persistence; however, subprocess/shell execution creates a security-relevant risk surface that should be manually reviewed—specifically whether `cmd` is fixed/allowlisted, whether untrusted inputs can influence command arguments, what `run_env` contains, and where captured outputs are handled.

Confidence: 52%Severity: 62%
Audit Metadata
Analyzed At
Jul 8, 2026, 07:15 PM
Package URL
pkg:socket/skills-sh/NVIDIA%2Fskills%2Fnv-segment-ctmr%2F@f9044b6f309cccd8a51a52c635e5d21034136e9a32895f9c9d26fc229fd980d1
Security Audit — socket — nv-segment-ctmr