story-publish

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/publish_bridge.py

This module itself does not show direct malicious logic, obfuscation, or explicit data exfiltration. However, it functions as a high-privilege execution harness for externally provided adapter scripts and relies on weak, text-based gating (keywords in adapter --help) rather than verifiable runtime enforcement. Because adapter paths and interpreter locations are taken from CLI/config and executed without integrity checking or sandboxing, the overall supply-chain security risk is meaningful: a malicious or tampered adapter (or modified .story-publish.json) could lead to harmful actions under the caller’s privileges.

Confidence: 72%Severity: 63%
Audit Metadata
Analyzed At
Aug 30, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/qin1473692580-ux%2Foh-story-claudecode%2Fstory-publish%2F@0f4422c0f2a269b7f541fd9d6b34e0403d2b7397bed7fe9c2347fee1b7930c42
Security Audit — socket — story-publish