mirrord-quickstart

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This quickstart is coherent with its stated purpose: installing mirrord, verifying kubectl, and starting a session. The primary security concern is the recommended curl | bash install from raw.githubusercontent.com — an unpinned download-and-execute pattern that raises supply-chain risk. Other guidance (brew/choco installs, IDE plugins, and using kubectl) is expected for this functionality but involves access to sensitive kubeconfig/cluster credentials; the skill does not provide verification steps (checksums, signatures) for the raw install. There is no evidence in the provided documentation of intentional malicious behavior or credential exfiltration, but the presence of an unverified installer and instructions that cause use of sensitive cluster credentials justify a moderate security risk rating. Recommend replacing curl|bash guidance with pinned releases, checksums/signatures, or package-manager-first instructions and adding explicit warnings about kubeconfig sensitivity and least-privilege policies.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:25 AM
Package URL
pkg:socket/skills-sh/metalbear-co%2Fskills%2Fmirrord-quickstart%2F@07d0c4e810d5cb0cffbaeaf9c5940d95e113d6a2