orbit
Audited by Socket on Sep 18, 2026
2 alerts found:
Anomalyx2The fragment appears to be a legitimate autonomous Git/LLM runner template, not an intentionally malicious implant. It has high operational privilege because it executes configurable shell commands and repository-local scripts, and it may disclose goal and diff content to configured LLM tools. These are material security risks if environment variables, repository files, or helper scripts are attacker-controlled, but no direct malware indicators or covert exfiltration behavior are present.
The fragment is executor-engine documentation with no direct evidence of malware or concealed malicious payloads. It documents powerful autonomous command execution and multiple permission-bypass modes, and its bash -c execution model would be dangerous if EXEC_CMD were derived from untrusted input. Treat EXEC_CMD as strictly trusted configuration, prefer wrappers and restricted tools, and avoid broad permission bypass where possible.