gnomad-graphql-skill

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/gnomad_graphql.py

No clear evidence of malware or supply-chain backdoor behavior is present. The code is a straightforward gnomAD GraphQL client, but its caller-controlled query_path and raw_output_path create arbitrary file read/write risks, including possible path traversal and unintended file modification. These risks should be mitigated by restricting paths to approved directories, rejecting traversal and absolute paths where appropriate, and using safe temporary-file handling.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 20, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/openai%2Fplugins%2Fgnomad-graphql-skill%2F@f82dccd11369a33ea1baf790c18203f16e042e2387a7f2c8d67a04872d9d164a
Security Audit — socket — gnomad-graphql-skill