installing-skills
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalyREADME.md
LOWAnomalyLOW
README.md
The code fragment presents a legitimate remote-install capability but introduces notable supply-chain and runtime risks due to unvalidated downloads and a hardcoded install path. It is not inherently malicious, but requires robust safeguards (integrity verification, allowlisting, sandboxing, and least-privilege execution) to reduce risk before production use.
Confidence: 59%Severity: 60%
Audit Metadata