council-2

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/chamber-orchestrator.sh

The script itself does not contain explicit malware; however it contains unsafe handling of external inputs (TOPIC and MEMBER_IDS) and executes an external helper script, leading to moderate security risk. Primary issues: SQL injection possibilities (both SELECT and INSERT) and the ability to execute a local script (graphiti-bridge.sh) that, if tampered with, yields arbitrary code execution. Recommend validating/escaping inputs, using parameterized queries or sqlite3 parameter APIs, and ensuring graphiti-bridge.sh is from a trusted, immutable location.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcouncil-2%2F@a2804decc8dcaf6660fdc22b0ad2dc0af64db7a4