ghost-scan-deps

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
agents/init/agent.md

The supplied content is an installation instruction, not the installer source itself. It uses the high-risk `curl | bash` pattern against a mutable GitHub branch, allowing remote code to execute and install or replace binaries without demonstrated cryptographic verification. No confirmed malware is visible from the instruction alone, but the installer should be reviewed and pinned to a trusted commit with verified signatures or checksums before use.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-scan-deps%2F@2b224e72a15e6e4d7ddab21c0d29c543326c9855ad40cd717660423a83b425cc
Security Audit — socket — ghost-scan-deps