takt-facet-builder

Fail

Audited by Socket on Mar 10, 2026

2 alerts found:

Obfuscated Filex2
Obfuscated FileHIGH
references/takt/builtins/ja/pieces/frontend-mini.yaml

The configuration file itself does not contain embedded malicious code, hard-coded secrets, or obfuscated payloads. However it grants broad, high-risk capabilities (network access, file read + remote provider, Bash execution, and edit/write permissions — including parallel editors). These capabilities create clear supply-chain and data-exfiltration risks if a provider, model, or agent runtime is compromised or malicious. Apply least-privilege, restrict network and shell capabilities, require human review for sensitive edits, and add logging and approval gates before allowing automated edits.

Confidence: 98%
Obfuscated FileHIGH
references/takt/builtins/ja/facets/instructions/implement-e2e-test.md

No actionable analysis possible due to missing code fragments in all provided preliminary reports. Await actual code to perform a rigorous security assessment and to produce an improved, evidence-based summary.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:15 AM
Package URL
pkg:socket/skills-sh/j5ik2o%2Fai-tools%2Ftakt-facet-builder%2F@9a45db7e3ac037f966d244992a0a19abdd77ffcb