ghost-scan-secrets

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
agents/init/agent.md

The fragment executes an installer by piping an install.sh from raw.githubusercontent.com directly into bash. This is a high-risk supply-chain pattern because it gives arbitrary remote code the ability to run with the invoking user's privileges and modify the system (files, environment, installed binaries). There is no visible integrity verification or pinning. Because the actual install.sh and any binaries are not provided, this report cannot confirm malicious content, but the execution pattern warrants treating the operation as a significant security risk until the remote script and artifacts are audited and integrity-verified.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 20, 2026, 02:04 PM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-scan-secrets%2F@de32232f15c19d6f6dc344f236bfd2cd23ee4a5f