experiment-queue

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/queue_manager.py

No clear evidence of embedded malware (no exfiltration/backdoor/cryptomining) in the fragment, but it is a highly privileged job runner that executes attacker-influenced shell strings via shell=True, uses eval-based conda hook resolution from env/manifest without validation, and launches arbitrary job['cmd'] verbatim. In a supply-chain context, a malicious manifest/dependency configuration could lead to arbitrary command execution and sabotage. Treat as high-risk if manifest/environment are not fully trusted.

Confidence: 68%Severity: 70%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:08 PM
Package URL
pkg:socket/skills-sh/wanshuiyin%2Fauto-claude-code-research-in-sleep%2Fexperiment-queue%2F@836f9af8c5a656c71b38a107969f8bbaf4ed20834e72810645cdcc63267ea4a8
Security Audit — socket — experiment-queue