recruiter-assistant

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/process_incoming.js

The code implements expected functionality for a resume-processing CLI but uses unsafe patterns: unvalidated user-controlled filenames are interpolated into shell commands and path.join('/tmp', fileName) allows path traversal. These issues create realistic command injection and arbitrary file access risks. No direct evidence of intentional malware or network exfiltration is present in this fragment, but the insecure handling of inputs is a significant security concern that should be remediated.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 4, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/openclaw%2Fskills%2Frecruiter-assistant%2F@438a30d8ac23d92d3399e3234f96f060ad309e36