yzr-skill-creator

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/smoke_test_scoring.py

This module is a test harness that intentionally performs executable hijacking for evaluation by writing a temporary executable ('claude'), chmodding it, and prepending its directory to PATH before invoking run_eval, while also passing a generated judge configuration via SMOKE_JUDGE_CONFIG. The primary security determinant is the unknown STUB_SRC content and the unknown implementation details of run_eval (where subprocess/network/side effects would occur). No direct malicious indicators (hardcoded credentials, explicit exfiltration, obfuscation) are visible in the fragment itself, but the design pattern creates high execution control and therefore a moderate-to-high potential security risk if STUB_SRC or run_eval is compromised.

Confidence: 45%Severity: 60%
Audit Metadata
Analyzed At
Aug 22, 2026, 04:02 AM
Package URL
pkg:socket/skills-sh/yzr95924%2Fyzr-skill%2Fyzr-skill-creator%2F@0b9b2333c4361c251a1ef9006580d2f76b0e55d2df4a812796bcd7ae850e1db8
Security Audit — socket — yzr-skill-creator