weco

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/eval-training-time.md

The snippet itself contains no direct signs of obfuscated or explicitly malicious logic, but it executes an external module (.weco/optimize.py) and uses values from that module to perform filesystem deletion and to run training. That design allows a malicious or compromised optimize module to execute arbitrary code and delete arbitrary files. Risk is primarily a supply-chain / plugin-execution risk: safe if .weco/optimize.py is trusted and verified; dangerous if it is attacker-controlled. Recommend restricting and verifying the module before execution and sanitizing MODEL_PATH before deletion.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 12, 2026, 11:19 PM
Package URL
pkg:socket/skills-sh/wecoai%2Fweco-skill%2Fweco%2F@c42b6e9ca409f7d66ef060ef74ec3019494067fb