split-stack

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/strip_hunks.py

No clear malware behavior (no network/exfiltration, no eval/exec, no obfuscation, no credential theft) is present in this code fragment. However, it is a powerful in-repo modification/deletion tool whose write/delete operations are governed entirely by an external JSON spec. If an attacker can influence the spec path/content, they can cause targeted overwrites and removals within the repository (albeit constrained by repository path/symlink/escape checks). The main residual concern is misuse/supply-chain sabotage rather than stealth malware.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Aug 13, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/rolemodel%2Frolemodel-skills%2Fsplit-stack%2F@24d469941f643933d7b9f1c86f067fb0cc7d9e9c58d83dfa974f35ce3dbd656f
Security Audit — socket — split-stack