smart-commit

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/smart-commit-dispatch.sh

No direct malware indicators are present in this dispatcher fragment (no exfiltration, persistence, or obfuscated payloads). However, the allowlist provides only first-token gating and includes an interpreter (bash), meaning an attacker who can supply arguments can achieve arbitrary command execution expressible through bash (and can also influence which git/mktemp/rm binaries are used via PATH). Treat this as an execution router, not a sandbox; the security risk is primarily boundary misuse and delegated interpreter power.

Confidence: 76%Severity: 57%
Audit Metadata
Analyzed At
Aug 24, 2026, 01:46 PM
Package URL
pkg:socket/skills-sh/sd0xdev%2Fsd0x-harness%2Fsmart-commit%2F@b970d2356b7e438a16326ac07d0d5ee9b22e13a872d72d9a19aa60d001e6e65b
Security Audit — socket — smart-commit