debug

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/debug_cleanup.js

No indicators of malware or data exfiltration. The script contains a path traversal / insufficient input validation issue: sessionId (and to a lesser extent DEBUG_LOG_DIR/projectPath) are not sanitized, allowing crafted inputs to cause truncation or deletion of arbitrary files the process can access. This is a moderate-to-high security risk for environments where untrusted users can control CLI args or environment variables. Apply input validation, absolute-path checks, and runtime path containment verification before performing destructive filesystem operations.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:26 PM
Package URL
pkg:socket/skills-sh/vltansky%2Fdebug-skill%2Fdebug%2F@63438f4823cba0e66e30205f764e4cbcbc48fe31