amq-cli

Warn

Audited by Socket on Mar 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose (AMQ-based inter-agent messaging) is generally coherent with its described capabilities. However, there is a significant security concern due to the install path: it downloads and executes a remote script to install the amq CLI from an unverified source, which constitutes a classic supply-chain and potential credential/data risk. This pattern, especially when combined with potential local data handling by the unverified binary, makes the overall footprint suspicious and not confidently safe for deployment without additional verification (pinning, checksums, official registry packaging, or a trusted internal repository). If the install source is replaced with a verified, signed release from an official registry and the tool’s authors provide hash/signature validation, the risk would be substantially reduced and the footprint would be more clearly benign.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 12, 2026, 03:06 PM
Package URL
pkg:socket/skills-sh/avivsinai%2Fagent-message-queue%2Famq-cli%2F@067d76ce7d50028f7611c11cb1889e3353fb29d0