dev-sanity

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/sanity_check.sh

This module is primarily a CI/dev sanity-check tool, but it contains a high-impact supply-chain execution risk: it uses eval to execute shell code produced by an external resolver. If the resolver output or its inputs (overlay/context) are tampered with, this enables arbitrary command execution. Additionally, it performs outbound curl requests to configuration-provided URLs without allowlisting, which can expand the network attack surface (potential SSRF-like probing). No explicit malicious payloads are visible in the fragment itself, but the eval-based trust boundary makes it dangerous to run with untrusted or potentially compromised configuration/resolver.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:12 PM
Package URL
pkg:socket/skills-sh/build000r%2Fskills%2Fdev-sanity%2F@2b1d26eb05f2055c1e2bec117ab6e3bbecd6ebae