antigravity-swarm

Warn

Audited by Socket on Feb 13, 2026

4 alerts found:

filesystemAccessSecurityusesEvalshellAccess
filesystemAccessLOW
SecurityMEDIUM
scripts/dispatch_agent.py

This module is a thin dispatcher that intentionally executes side-effect directives emitted by an external 'gemini' CLI. While the source file contains no hidden obfuscation or explicit hard-coded malware, its core behavior (parsing untrusted stdout and performing file writes and shell execution with shell=True) creates a critical security risk: an attacker who can influence the gemini binary, its output, or PATH/GEMINI_PATH can achieve arbitrary code execution, file overwrite, and data exfiltration. Running this script in untrusted or production environments without strict controls (binary integrity checks, allowlists for file paths/commands, sanitization, sandboxing, logging redaction, and resource/time limits) is unsafe.

Confidence: 75%Severity: 78%
usesEvalMEDIUM
shellAccessMEDIUM
Audit Metadata
Analyzed At
Feb 13, 2026, 02:56 PM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Fantigravity-swarm%2F@e9e63f70371e18c6d5a20760197dc43f1b066fb1