civic-skill

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/civic_graphql.py

No strong signs of intentional malware (no obfuscation, no dynamic execution, no stealth/persistence, no obvious secret harvesting). However, the module has high-impact security behaviors when fed attacker-controlled input: it can read arbitrary local files via query_path and transmit their contents to a remote server as the GraphQL query, and it can write arbitrary files via raw_output_path when save_raw is enabled. These are misuse/exposure risks that depend heavily on who controls the stdin payload and what filesystem permissions the process has.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fcivic-skill%2F@9af6e6d7202b3af78a1f6ae720d095342b108f9bc061bf49b8e6d2bb8979a6ad
Security Audit — socket — civic-skill