web-search

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
install.bat

The batch file itself does not contain explicit backdoors, credential theft, or direct exfiltration code. However it performs high-risk operations: downloading and executing a PowerShell install script from https://astral.sh and installing a pip package directly from https://skale.dev/credgoo without integrity checks. These actions enable arbitrary remote code execution during install and represent a supply-chain/installer security risk. Recommend manual verification of the remote scripts/packages (review contents, use pinned versions and checksums, or avoid automatic 'iex' installs) before running in production.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Mar 2, 2026, 02:44 AM
Package URL
pkg:socket/skills-sh/devskale%2Fskale-skills%2Fweb-search%2F@8a18003ddbe6bacc39b99667b56948d4ee29dbe7