compound-product

Warn

Audited by Socket on Jun 30, 2026

3 alerts found:

Securityx2Anomaly
SecurityMEDIUM
SKILL.md
SecurityMEDIUM
scripts/auto-compound.sh
AnomalyLOW
scripts/loop.sh

This wrapper script is not a standalone malware payload, but it materially increases operational risk by repeatedly invoking an LLM agent/CLI with `--dangerously-skip-permissions` and by logging/printing all merged agent output. The practical threat is that malicious or prompt-injected content in CLAUDE.md (or unsafe claude CLI configuration) could lead to unintended host actions, with outputs potentially exposing sensitive data. Additional context (CLAUDE.md contents, claude CLI defaults, and what the agent is permitted to do) is required to determine whether the overall package behavior is truly dangerous.

Confidence: 62%Severity: 56%
Audit Metadata
Analyzed At
Jun 30, 2026, 08:28 PM
Package URL
pkg:socket/skills-sh/SZoloth%2Fskills%2Fcompound-product%2F@085cd899e5a84246a33135d91d97127c2bbfa78361ad0ff9a384042000fca97b
Security Audit — socket — compound-product