runpodctl

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
reference/install.md

No explicit malware behavior (e.g., credential theft, exfiltration, backdoor installation) is demonstrated in the provided snippet. However, the installation process includes a high-risk supply-chain pattern: a remotely fetched bootstrap script is executed directly via `curl -sSL https://cli.runpod.net | bash`, and downloaded release archives/binaries are extracted without any checksum/signature verification or version pinning shown. This makes the primary concern integrity/procedural risk rather than confirmed malicious code.

Confidence: 66%Severity: 58%
Audit Metadata
Analyzed At
Aug 21, 2026, 01:32 PM
Package URL
pkg:socket/skills-sh/runpod%2Frunpod-plugins-official%2Frunpodctl%2F@c4ef557932b765432643a29316e9c085b1c047ccb92b0b129bb24eba8e17a6a6
Security Audit — socket — runpodctl