llm-wiki

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/wiki_evolve_agent.py

The fragment is an AI-agent runner with intentional subprocess execution, environment forwarding, and optional workspace command/file capabilities. No direct malware indicators, credential harvesting logic, suspicious network destinations, persistence, or obfuscated payloads are present. The primary security risk is that inherited environment secrets and enabled agent tools may be exposed or misused if an external agent, prompt, workspace, or model is untrusted. Review the external runner implementations and consider minimizing the environment and enforcing OS-level sandboxing.

Confidence: 95%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 06:28 AM
Package URL
pkg:socket/skills-sh/praneybehl%2Fllm-wiki-plugin%2Fllm-wiki%2F@7094add4b2b8e7523621886e8520e904a6e090aaecd9aa50c9ae0ed58f105607
Security Audit — socket — llm-wiki