senpi-entrypoint
Fail
Audited by Socket on Mar 11, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The presence of backtick-based command substitutions in the skill's samples (e.g., reading OPENCLAW_STATE_DIR and SENPI_STATE_DIR via backticks) constitutes a potential command-injection-like pattern, and could lead to unintended shell evaluation if not properly sanitized in all contexts.
Confidence: 85%Severity: 80%
Audit Metadata