clinvar-variation-skill

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/clinvar_variation.py

The fragment is a legitimate API wrapper with no clear malicious behavior, credential theft, persistence, or code execution. It has a significant filesystem safety issue: save_raw=True permits arbitrary file and directory creation or overwriting through raw_output_path, including path traversal where permissions allow. Restrict output paths to an approved directory, reject traversal and absolute paths, and impose upper bounds on timeout and response/summary limits. Confidence is high for the identified behavior; malware likelihood is very low.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fclinvar-variation-skill%2F@ea4b31834877107867f6ab2186861a64b01bf2bb9c89f52192d1c77e1080a83a
Security Audit — socket — clinvar-variation-skill