edge-candidate-agent

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/auto_detect_candidates.py

No explicit malicious payload, credential access, network exfiltration, or obfuscation is evident in this module. The primary security/supply-chain risk is the optional execution of an attacker-controlled external command via --llm-ideas-cmd (no timeout/allowlist/sandbox), followed by ingestion of untrusted YAML output that is propagated into exported ticket YAML artifacts and potentially downstream export/validation logic. If --llm-ideas-cmd can be influenced by an attacker (or shipped with unsafe defaults in automation), this becomes the dominant risk.

Confidence: 66%Severity: 55%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:20 AM
Package URL
pkg:socket/skills-sh/tradermonty%2Fclaude-trading-skills%2Fedge-candidate-agent%2F@6b84ddbd570b1d630b0fb58fce56e0f24fe731c20997354585cdb91984eb4ea5
Security Audit — socket — edge-candidate-agent