rclone
Fail
Audited by Socket on Mar 3, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This is documentation for using rclone to transfer files to cloud storage providers. Functionality and requested credentials are consistent with the stated purpose. The primary supply-chain risk is the recommended curl | sudo bash install pattern; while the domain referenced is the official rclone site, pipe-to-shell installs are inherently risky and should be discouraged or replaced with safer, verified package installs. Storing access keys in rclone config is necessary for use but poses credential exposure risk if the host is compromised. No evidence of hidden exfiltration endpoints, obfuscated code, or explicit malicious directives was found.
Confidence: 95%Severity: 90%
Audit Metadata