zenmux-feedback

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/update-references.sh

This fragment is an automation script that fetches and updates third-party Git repositories listed in a local text file and appends corresponding entries to .gitignore. It does not show explicit malicious payload behavior (no exfiltration, credential theft, or obfuscated code), but it materially increases supply-chain exposure because it clones/pulls arbitrary remote repositories without allowlisting or integrity controls (no pinning/signature verification). Additionally, git clone/pull may interact with local git-hook/config settings depending on the environment.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Apr 3, 2026, 08:16 AM
Package URL
pkg:socket/skills-sh/ZenMux%2Fskills%2Fzenmux-feedback%2F@479e8d668ab0a4deb3f65b00a69974efa8d285d6