NYC

md2wechat

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run.sh

The script itself is not malicious code — it is an installer/launcher that downloads and executes a binary from a GitHub release. However, because it executes a remotely downloaded binary without cryptographic verification (only a size check), it presents a moderate supply-chain risk: a compromised or tampered release could lead to arbitrary code execution on systems that run this script. There are no hardcoded secrets or obfuscated payloads in the script. Recommend adding integrity checks (e.g., SHA256 checksum or GPG signature verification) or avoiding auto-exec of fetched binaries if threat model requires higher assurance.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:39 PM
Package URL
pkg:socket/skills-sh/geekjourneyx%2Fmd2wechat-skill%2Fmd2wechat%2F@1aec5b8292b15b267522dcb1be0d782536f82748