harmonyos-build-deploy

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/device-installation.md

The code implements a standard device deployment flow: discover artifacts, transfer to a transient remote sandbox, install in a defined order, then cleanup, with optional auto-launch. No explicit malicious behavior detected within this fragment. However, security and supply-chain risks are present due to lack of artifact integrity verification, permissive remote execution, and potential remote-path misconfigurations. Recommended mitigations include artifact signature checks, explicit remote-path validation, non-destructive dry-run or staged deployment, and tighter input validation.

Confidence: 65%Severity: 62%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:39 PM
Package URL
pkg:socket/skills-sh/fadinglight9291117%2Farkts_skills%2Fharmonyos-build-deploy%2F@dcc0117f551e7abd855f116211949a054fc0519e