experiment-queue
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
SecuritySecurityscripts/queue_manager.py
MEDIUMSecurityMEDIUM
scripts/queue_manager.py
No clear evidence of embedded malware (no exfiltration/backdoor/cryptomining) in the fragment, but it is a highly privileged job runner that executes attacker-influenced shell strings via shell=True, uses eval-based conda hook resolution from env/manifest without validation, and launches arbitrary job['cmd'] verbatim. In a supply-chain context, a malicious manifest/dependency configuration could lead to arbitrary command execution and sabotage. Treat as high-risk if manifest/environment are not fully trusted.
Confidence: 68%Severity: 70%
Audit Metadata