nexus-caiwu-agent

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/wrapper.py

The code acts as an orchestrator for a local Nexus project handling stock financial data analysis and a chat interface. Its primary risk stems from dynamic imports and subprocess execution of code inside a user-controlled project_path, enabling potential data exfiltration, tampering, or unintended behavior if the local project is compromised. A critical bug (undefined epilog) will crash executions. Recommend fixing the epilog reference, validating and sandboxing dynamic imports, and adding integrity checks (e.g., hash verification) for the local project code before enabling any data processing in production.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
Mar 9, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/hhhh124hhhh%2FNexus-caiwu-skill%2Fnexus-caiwu-agent%2F@ed293bb1c036cf6d16f047a033378bdea0c44038