soia-pkm-maintain

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/codex_notify_wrapper.sh

This module is primarily a functional wrapper, but it contains high-impact execution primitives: it evals output from a bundled Python helper (shell code execution in the wrapper) and can execute an “original notify” command constructed from caller-provided tokens (arbitrary command execution if those inputs are attacker-controlled). The session logging script is invoked with vault/log-dir parameters that originate from environment/argv, and failures are intentionally suppressed, reducing detection/forensics. While there is no direct evidence of exfiltration or backdoor logic in this fragment, the attack surface is significant; review maintain_env.py and session_end_log.sh and ensure wrapper inputs/config are trusted and integrity-protected.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Jul 22, 2026, 01:36 PM
Package URL
pkg:socket/skills-sh/soia-team%2Fsoia-open-pkm-vault-skills%2Fsoia-pkm-maintain%2F@7d1eba507d0429f7012a05fe156acb2d6c0c8c8ffc93b3f8fb445f4b80f4316c
Security Audit — socket — soia-pkm-maintain