setup-solidity-contracts

Fail

Audited by Socket on Mar 5, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document is a legitimate setup guide for Solidity projects using OpenZeppelin and contains standard installation and configuration instructions. The primary security concerns are supply-chain related: (1) the inclusion of a curl|bash installer command for Foundry (download-and-execute risk), and (2) the potential for unpinned package installs (forge install without a pinned tag) to pull unintended or malicious code. There are no signs in this file of deliberate malware, hard-coded secrets, or obfuscated payloads. Recommended actions: avoid pipe-to-shell; download and verify installers before running; always pin dependency versions or use commit hashes; inspect third-party package contents if in a high-threat environment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 5, 2026, 07:48 AM
Package URL
pkg:socket/skills-sh/OpenZeppelin%2Fopenzeppelin-skills%2Fsetup-solidity-contracts%2F@e19fa44a9030970b62315e28149bae9bbffc70b4