llm-wiki
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
AnomalyAnomalyscripts/wiki_evolve_agent.py
LOWAnomalyLOW
scripts/wiki_evolve_agent.py
The fragment is an AI-agent runner with intentional subprocess execution, environment forwarding, and optional workspace command/file capabilities. No direct malware indicators, credential harvesting logic, suspicious network destinations, persistence, or obfuscated payloads are present. The primary security risk is that inherited environment secrets and enabled agent tools may be exposed or misused if an external agent, prompt, workspace, or model is untrusted. Review the external runner implementations and consider minimizing the environment and enforcing OS-level sandboxing.
Confidence: 95%Severity: 62%
Audit Metadata