install-nodejs-22

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns reasonably with its stated purpose of setting up a Node.js development environment by installing fnm, Node.js 22, and pnpm across platforms. However, there are notable supply-chain and verification gaps: downloads are performed without explicit signature checks or pinned hashes, and there is reliance on external binaries obtained via curl. Privilege elevation is involved for corepack enabling, which is standard but should be exposed clearly to the user. Given the combination of legitimate tooling installation and these verification gaps, the footprint is suspicious but not definitively malicious. It should be treated as a benign capability with elevated risk due to potential supply-chain weaknesses unless proper verification steps (checksums/signatures, pinned versions, and trusted sources) are added.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:21 AM
Package URL
pkg:socket/skills-sh/cmkim%2Fmj-download-test%2Finstall-nodejs-22%2F@5d71fc32c0b21cb29da5325dff749f1eb1fca670