perl-environment-setup

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is a legitimate environment-setup guide with expected operations for managing Perl versions. The major supply-chain concern is the unverified download-and-execute pattern (curl | bash) and the absence of integrity checks or pinned artifacts for installers and third-party modules. The project bootstrap convenience (automatic install and cpanm --installdeps) increases risk by executing remote code without explicit per-step confirmation. No clear signs of backdoor, credential theft, obfuscation, or malicious behavior are present in the provided content. Mitigations: avoid piping remote scripts to shell, verify downloads, pin versions/checksums, and make bootstrap installs explicit and auditable.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 02:05 PM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fperl-environment-setup%2F@4bfae52cfd83fb9f3489a59567ae6154b44690e9