plugin-test

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/container-runner.mjs

No clear evidence of stealthy malware (e.g., hardcoded credential theft, reverse shell, or outbound exfiltration) is visible in this fragment. However, the module is security-relevant because it performs high-privilege orchestration: it installs global npm packages (supply-chain surface), installs a plugin from a caller-provided path, executes an optional probe command from configuration (potential arbitrary command execution depending on runner spawning semantics), and persists captured stdout/stderr to disk (possible secret leakage). If config/probe/plugin inputs are not strictly trusted and if subprocess spawning is not hardened, the overall security risk is moderate to high.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Sep 2, 2026, 08:16 AM
Package URL
pkg:socket/skills-sh/oh-my-dsh%2Fdsh-plugin-upgrade-skill%2Fplugin-test%2F@3b6572f6c9427efcc2ca88428bc6bac98b4c06dc06bde2d6f0bbc60fadbc52ba
Security Audit — socket — plugin-test