formal-verify

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/verify-behavioral.py

No clear malicious payload or unauthorized data-theft behavior is present. The main risk is intentional dynamic execution of every Python specification file in a user-selected directory; untrusted specifications can execute arbitrary code, access local data, and affect the host process. The tool should only load trusted specification files, and traceback output should be considered potentially information-revealing.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/petekp%2Fagent-skills%2Fformal-verify%2F@bc88e9c5a6402de76bab11065488e3b684925a96dabd06613f0f02798644d118
Security Audit — socket — formal-verify