cti-domain-research

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
cti-search.md

The fragment specifies a CTI search and optional NotebookLM publication workflow. It does not itself show clear malicious behavior, but it introduces a potentially significant command-injection risk by interpolating user-controlled $ARGUMENTS into a Bash command. The NotebookLM path also transfers search-derived URLs and local notebook configuration to an external connector. Use strict argument parsing, avoid shell interpolation, pass arguments as an array, and validate notebook IDs and source data before execution.

Confidence: 93%Severity: 62%
Audit Metadata
Analyzed At
Sep 19, 2026, 10:34 AM
Package URL
pkg:socket/skills-sh/security-phoenix-demo%2Fsecurity-skills-claude-code%2Fcti-domain-research%2F@eaf9f08812bb8053b5f6fd0d33dc194e54e74284a99be504dcb1bce21738fc9f
Security Audit — socket — cti-domain-research