unifi-api

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
.claude/settings.local.json

The manifest itself is not an active malware payload but is overly permissive and enables several high-risk behaviors (arbitrary shell execution and dynamic package installation). It significantly increases supply-chain and remote-code-execution attack surface if downstream code or inputs are untrusted. Tighten permissions (remove pip3 wildcard, restrict Bash args, and narrow WebFetch domains) and enforce validation and sandboxing before allowing these operations.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:17 PM
Package URL
pkg:socket/skills-sh/trtmn%2Fagent-skills%2Funifi-api%2F@07ac7cf4e7d96e1b26f395bfa4e8b8df8d29d3b2