Lightpanda

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Anomaly
AnomalyLOW
README.md

The fragment itself is non-executable and does not contain malicious logic. The main concern is the external install.sh and the binary download chain, which could introduce supply-chain risk if integrity checks, code signing, and trusted sources are not enforced. Recommend explicit integrity verification (SHA-256/512 or code-signing), documented trusted sources, and least-privilege execution for the installation process.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Mar 17, 2026, 09:49 PM
Package URL
pkg:socket/skills-sh/delexw%2Flightpanda-agent-skill%2Flightpanda%2F@acb3568e2d6fde61360da5b5ae978bdff0e43ff1