fw-setup

Warn

Audited by Socket on May 6, 2026

1 alert found:

Anomaly
AnomalyLOW
commands/fw-setup-upgrade.md

No clear evidence of intentional malware exists in this fragment. However, it performs a high-impact supply-chain action: it downloads and globally installs remote code via `npm install -g` from a CDN-selected tarball, with only an HTTP reachability check and no demonstrated integrity/authenticity verification (notably for “latest”). Treat this as a meaningful supply-chain integrity risk rather than confirmed malicious behavior.

Confidence: 60%Severity: 66%
Audit Metadata
Analyzed At
May 6, 2026, 06:31 AM
Package URL
pkg:socket/skills-sh/freshworks-developers%2Fmarketplace%2Ffw-setup%2F@08de82adc3f9fcb8fab1f5bdd44e6d07d7a3a81a