jazz-schema-migrations

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
install.sh

The script itself is not malicious: it is an installer wrapper that delegates installation to local or remote installers. The primary security risk is supply-chain: it executes external code (local binary, local TypeScript, or npm package) without verification. Recommended mitigations: audit installer/src/installer.ts before running; prefer preinstalled 'agent-skills' from a trusted package manager; avoid npx fallback in sensitive environments or pin and vendor the installer artifact; run installers in constrained environments (containers/limited-privilege users) where possible; verify package signatures/checksums if available.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:16 AM
Package URL
pkg:socket/skills-sh/alcyone-labs%2Fagent-skills%2Fjazz-schema-migrations%2F@f73c21efc1241ea00a52c548b08e83f9e95d769b