pty-capture

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
platforms/macos.md

This module combines QEMU virtual HID keystroke injection with raw terminal byte capture in the guest, outputting a hex dump of captured PTY/HID-delivered bytes over SSH. While the shown fragment lacks explicit malware indicators like external C2/persistence/obfuscated execution, its keystroke/terminal capture capability is strongly dual-use and could be repurposed for keylogging or sensitive input harvesting if pointed at real interactive sessions. Treat as a security-sensitive, potentially abuse-prone component pending review of the surrounding automation/orchestration code and intended test boundaries.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:34 AM
Package URL
pkg:socket/skills-sh/Factory-AI%2Ffactory-plugins%2Fpty-capture%2F@72aceaf603ffcf7ea343010f48596b52ac42664e