install-script-generator

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill presents a coherent, high-utility approach for generating installers and supporting documentation. However, its reliance on delivering and executing a script directly from a GitHub raw URL (curl|bash) without explicit verification or pinning introduces notable supply-chain and execution-risk. Given the potential for malicious hosting or tampered scripts, the footprint is suspicious relative to the stated safe-builder intent. No credentials or secret data are required by the skill itself, which is positive, but the common one-liner delivery pattern requires mitigations (e.g., checksum verification, GPG signing, or in-script verification) to be deemed benign in practice.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:46 PM
Package URL
pkg:socket/skills-sh/luongnv89%2Fskills%2Finstall-script-generator%2F@3d97c2db15e5f2ff726c4f2590fca3031dc2ad5c