fw-setup
Warn
Audited by Socket on May 6, 2026
1 alert found:
AnomalyAnomalycommands/fw-setup-upgrade.md
LOWAnomalyLOW
commands/fw-setup-upgrade.md
No clear evidence of intentional malware exists in this fragment. However, it performs a high-impact supply-chain action: it downloads and globally installs remote code via `npm install -g` from a CDN-selected tarball, with only an HTTP reachability check and no demonstrated integrity/authenticity verification (notably for “latest”). Treat this as a meaningful supply-chain integrity risk rather than confirmed malicious behavior.
Confidence: 60%Severity: 66%
Audit Metadata