hiclaw-test

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run-hiclaw-test.sh

This module is not overtly malicious, but it is structurally high-risk for supply-chain contexts: it executes arbitrary shell code by `source`-ing a user/environment-specified env file, and it then executes repository-controlled scripts after cloning/updating an unpinned upstream branch or selecting a potentially attacker-influenced local directory. If attacker control over ENV_FILE contents, REPO_DIR location, or upstream repository integrity exists, arbitrary code execution is feasible. If inputs and environment are fully trusted (e.g., locked-down CI), the practical risk is reduced.

Confidence: 70%Severity: 67%
Audit Metadata
Analyzed At
Apr 6, 2026, 08:13 AM
Package URL
pkg:socket/skills-sh/agentscope-ai%2FHiClaw%2Fhiclaw-test%2F@036611841d64541a2eebd668d61c47165f57951e