spectrum

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
providers/terminal.md

The module is primarily a subprocess-controlled local TUI provider. While the snippet does not show explicit malicious logic, it explicitly depends on an auto-downloaded and executed external tuichat binary (significant supply-chain execution risk) and it forwards application console logs into a chat transcript (potential inadvertent disclosure of secrets). Additional risk exists around attachment/image ingestion and JSON-RPC handling, which depend on input validation and sanitization not shown here.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
May 9, 2026, 04:25 AM
Package URL
pkg:socket/skills-sh/photon-hq%2Fskills%2Fspectrum%2F@2a826bb54053a7cf1f289a70d7c2763578b040a3