building-web-artifacts

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/init-artifact.sh

This appears to be a legitimate scaffolding/setup script with no direct indicators of intentional malware (no exfiltration, backdoor logic, or obfuscated execution). However, its supply-chain integrity is meaningfully weakened by (1) blind extraction of a local tarball into `src/` without checksum/signature verification (allowing arbitrary code injection into the app), and (2) broad dependency installation from public registries with limited version pinning (increasing exposure to compromised or unexpected upstream packages/install-script execution). The main concern is supply-chain tampering rather than overt malicious behavior in the script.

Confidence: 72%Severity: 56%
Audit Metadata
Analyzed At
Sep 13, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/1git2clone%2Fdotfiles%2Fbuilding-web-artifacts%2F@e0ae741342316e7eff0003139242a15c22662111b1ef70134df881a1db00a3c9
Security Audit — socket — building-web-artifacts