installing-skills

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
README.md

The code fragment presents a legitimate remote-install capability but introduces notable supply-chain and runtime risks due to unvalidated downloads and a hardcoded install path. It is not inherently malicious, but requires robust safeguards (integrity verification, allowlisting, sandboxing, and least-privilege execution) to reduce risk before production use.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
May 7, 2026, 04:35 AM
Package URL
pkg:socket/skills-sh/oaustegard%2Fclaude-skills%2Finstalling-skills%2F@c51ebef0a0fc20b0af964318c9c3e2b8bf8853c7