senpi-entrypoint

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The presence of backtick-based command substitutions in the skill's samples (e.g., reading OPENCLAW_STATE_DIR and SENPI_STATE_DIR via backticks) constitutes a potential command-injection-like pattern, and could lead to unintended shell evaluation if not properly sanitized in all contexts.

Confidence: 85%Severity: 80%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:35 PM
Package URL
pkg:socket/skills-sh/senpi-ai%2Fsenpi-skills%2Fsenpi-entrypoint%2F@8e03ac111a0d8340391d7e02688e1d880d0a987b