goals-and-kpis
Warn
Audited by Socket on Mar 9, 2026
1 alert found:
AnomalyAnomalyREADME.md
LOWAnomalyLOW
README.md
The fragment lacks in-code malicious activity but introduces typical OSS supply-chain risk via remote installer scripts (curl | bash). The documentation is otherwise benign. Recommend prioritizing safer installation patterns (npm install from trusted registry, verify installer integrity) and auditing the remote install script before use.
Confidence: 65%Severity: 62%
Audit Metadata