jev-capability-advisor

Warn

Audited by Socket on Sep 30, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/decision_cache.py

The code is a cache implementation, not apparent malware. However, unvalidated `key` values are used in filesystem paths; traversal components may permit reads or replacement writes outside the cache directory when the process has suitable permissions. Validate keys against the intended filename format before path construction.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 30, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/stark-ai-de%2Fagent-skills%2Fjev-capability-advisor%2F@5dbe8bfb826acdb45d146b8693dd5ce5693a6b0622b4d75f50587ee7267b739c
Security Audit — socket — jev-capability-advisor