oracle-soul-sync-update

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is a convenience updater that performs dynamic, runtime installation of an external CLI package from a GitHub repo. The code itself is not overtly malicious, but it employs a high-risk supply-chain pattern: fetching the latest tag at runtime and installing that artifact globally without integrity verification or pinned commits. The primary recommendations: avoid automated/unattended installs, pin to specific commits or signed releases, verify checksums or signatures before installing, prefer non-global installations or sandboxing, and require explicit human approval before restarting an agent to load third-party code. Treat this as a moderate supply-chain risk and apply hardening before use.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:48 PM
Package URL
pkg:socket/skills-sh/soul-brews-studio%2Foracle-skills-cli%2Foracle-soul-sync-update%2F@ecc83ec15fed924859f200e5aefdc5e62b749147