just-bash-executor

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Anomaly
AnomalyLOW
src/executor-init.ts

The code is primarily an SDK loader/compat layer that dynamically rewrites and executes JavaScript modules from base64 data: URLs, and it shims '@executor-js/api'. It does not contain explicit malware behaviors (no exfiltration, no credential theft, no process spawning), but it introduces a high-impact dynamic code execution mechanism and passes attacker-controlled configuration into network-capable plugins (graphql/openapi/mcp), which could become dangerous depending on how queuedSources are sourced. Treat as medium security risk with moderate malware likelihood due to the powerful data: import pattern.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Aug 11, 2026, 01:58 PM
Package URL
pkg:socket/skills-sh/vercel-labs%2Fjust-bash%2Fjust-bash-executor%2F@74373c998006c4a520c4ea0a0670c0cb44eac72b7df5b4afbf2c45d3d8c89454
Security Audit — socket — just-bash-executor