create-headless-agent

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
references/modules.md

No direct evidence of intentional malware in the provided modules (no obfuscated logic, credential theft, reverse shells, or destructive code paths). The primary security concern is potential sensitive-data exfiltration and leakage: completion webhooks can POST full agent output (including arbitrary text) to an attacker/misconfigured endpoint, and persistent session/state/log files can retain sensitive content without integrity or redaction. A secondary concern is prompt/data injection: dynamically embedding local context files from process.cwd into system instructions can steer model behavior if those files are attacker-influenced. Overall, treat this as a capability-focused agent utility with meaningful data-handling and egress risks rather than confirmed malware.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:24 AM
Package URL
pkg:socket/skills-sh/openrouterteam%2Fskills%2Fcreate-headless-agent%2F@a6b31684a593a0d1d1e549d768efeb674d518f98