ileap

Fail

Audited by Socket on Mar 4, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The iLEAP spec and accompanying documentation are normative specifications and implementation guidance and are not themselves executable or malicious. However, documentation includes pragmatic examples that instruct users to fetch and execute an external ACT runner script via curl | bash (raw.githubusercontent.com). This download-and-execute pattern, and the provided CI example that runs the same script with repository secrets, are legitimate convenience patterns but constitute a supply-chain risk: an attacker could modify the remote script or compromise the hosting account and harvest credentials or run arbitrary commands in users' environments. There are no hardcoded secrets or obfuscated payloads in the spec; network endpoints referenced are legitimate project domains. Recommendation: prefer pinned, verifiable releases (SHA256 checks, signed releases, or fetching a release asset and verifying signature) or instruct users to inspect downloaded scripts before execution; avoid curl|bash in CI with secrets without additional safeguards.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:24 AM
Package URL
pkg:socket/skills-sh/way-platform%2Fskills%2Fileap%2F@eebd19f282e5a36220518968934ec9a964d27888