minimal-run-and-audit

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_command.py

The shown code is an execution-and-evidence collection tool, not overt malware. It intentionally runs a caller-supplied command and writes runtime artifacts, so it is dangerous if exposed to untrusted command or repository inputs without isolation. Direct mode is presented as the default and native shell mode requires explicit opt-in, which reduces accidental shell injection but does not eliminate the inherent arbitrary-code-execution capability. No credential theft, exfiltration, persistence, obfuscation, or destructive behavior is visible in this fragment. Assessment is limited because the key run_persistent_command implementation is imported and not supplied; the fragment also appears syntactically truncated at the final line.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 05:17 PM
Package URL
pkg:socket/skills-sh/lllllllama%2Frigorpilot-skills%2Fminimal-run-and-audit%2F@677939105fd87c108afd57b8db8545f1f32fd955e09aecc4f355592b4baa660b
Security Audit — socket — minimal-run-and-audit