AGENT LAB: SKILLS

grepai-installation

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill is an installation guide whose stated purpose matches the operations it requests (installing a CLI). The primary security concern is the use of 'curl | sh' and 'irm | iex' to execute remotely hosted scripts without integrity verification — a high-risk installation pattern because it allows remote-to-local code execution with potential elevated privileges. There are no hardcoded credentials or explicit malicious code in the provided documentation, so the package appears not malicious by itself, but the installation method is hazardous if the remote scripts are tampered with or compromised. Treat the install scripts as untrusted until verified; prefer Homebrew or building from audited source with pinned commits/releases.

Confidence: 85%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:05 PM
Package URL
pkg:socket/skills-sh/yoanbernabeu%2Fgrepai-skills%2Fgrepai-installation%2F@362e6f26cd810dbf8b08e6a2aceb53e7a8dd8197