dstack-core

Warn

Audited by Socket on Aug 17, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run-workflow.py

This module is a high-risk workflow launcher: it executes an arbitrary caller-supplied Python file via runpy.run_path and also prepends the target directory to sys.path, which can enable import shadowing. The fragment itself shows no explicit malware behaviors (e.g., exfiltration, backdoor logic, or credential theft), but it creates an execution primitive that becomes dangerous if the workflow path and its directory are not strictly controlled and trusted.

Confidence: 80%Severity: 55%
Audit Metadata
Analyzed At
Aug 17, 2026, 12:10 AM
Package URL
pkg:socket/skills-sh/robertderose%2Fdstack%2Fdstack-core%2F@60f545616efd10ce66604c92c217abe069cd0672f66b3cbb0caf2d2a6e48c08f
Security Audit — socket — dstack-core