cascading-fleet

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
lib/cascade-template.sh

This Bash module is not itself a payload with overt malicious code, but it is a high-impact supply-chain propagation tool. Its main security concerns are (1) executing an external Node/TypeScript CLI from a path derived from the PROJECTS environment variable and (2) bypassing git verification via --no-verify on both commits and pushes. If the wheelhouse CLI or the template input is compromised—or if PROJECTS is manipulated—this script could rapidly create and publish malicious changes across a fleet via direct pushes and/or automated PRs. No direct exfiltration/backdoor logic is visible in this fragment.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
May 20, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/SocketDev%2Fsocket-mcp%2Fcascading-fleet%2F@87383731443b4d043289dd64ef92976d20e4a50a
Security Audit — socket — cascading-fleet