setup

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
reference/setup.sh

This module is a typical developer-setup script that automates installation of well-known CLI tools. There is no direct evidence of credential theft, exfiltration, or backdoor behavior in the visible fragment. However, it does introduce meaningful supply-chain risk by executing a network-fetched installer script directly (`curl ... | sh`) and by installing downloaded artifacts (.deb) and selecting versions from live API data without explicit checksum/signature verification or version pinning in this script. These are the primary security concerns to address (pin versions, verify integrity, and avoid direct remote script execution where feasible).

Confidence: 65%Severity: 62%
Audit Metadata
Analyzed At
May 1, 2026, 11:59 AM
Package URL
pkg:socket/skills-sh/dedalus-erp-pas%2Fhexagone-foundation-skills%2Fsetup%2F@bb7c1b9579bcf98e7f522bd65bc1520fa97a4d38