safe-file-reader

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
_expected.json

The provided metadata/test manifest explicitly states the 'safe-file-reader' is unsafe and lists critical path traversal and sensitive-file access findings. Treat this package as high security risk for data exfiltration until it implements strict path canonicalization, allowlisting/base-directory enforcement, and removes any use of user-supplied paths in shell/command contexts. Further static/dynamic analysis of the actual implementation is required to confirm any additional malicious behaviors or command execution vectors.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 10:37 PM
Package URL
pkg:socket/skills-sh/cisco-ai-defense%2Fskill-scanner%2Fsafe-file-reader%2F@4bb7f5f40a99de47f631cebf0ce371a61a798316