ghost-scan-deps
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
SecuritySecurityagents/init/agent.md
MEDIUMSecurityMEDIUM
agents/init/agent.md
The supplied content is an installation instruction, not the installer source itself. It uses the high-risk `curl | bash` pattern against a mutable GitHub branch, allowing remote code to execute and install or replace binaries without demonstrated cryptographic verification. No confirmed malware is visible from the instruction alone, but the installer should be reviewed and pinned to a trusted commit with verified signatures or checksums before use.
Confidence: 98%Severity: 78%
Audit Metadata