gemini

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
install.js

The script itself is not overtly malicious (no direct exfiltration, backdoor, or obfuscated payloads present in this file). However it performs unsafe operations that create a high supply-chain risk: it downloads and writes remote code without verification and runs pip install on remotely provided requirements, enabling execution of arbitrary code from external sources. Use caution: inspect downloaded files and the requirements before running, and prefer integrity-checked installation. Overall assessment: not clearly malware in itself, but moderate-to-high supply-chain risk.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 9, 2026, 01:12 PM
Package URL
pkg:socket/skills-sh/nicobailon%2Fgemini-multimodal%2Fgemini%2F@bd8b9ed7677a97764261b074713997bd0518b6ce