amrouter

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/setup.sh

No direct malicious payload indicators (e.g., backdoor logic, exfiltration to remote services, reverse shells) are evident in this Bash script. However, the script performs high-impact supply-chain operations: it clones a remote repository and runs npm install/build without pinning or integrity verification, then starts the resulting backend code locally. Additionally, the generated agent templates include an insecure token-like default API key when AMROUTER_KEY is not set, and sed backups may leave sensitive values on disk. Overall, treat this as a generally functional installer with significant supply-chain review and hardening needs rather than as confirmed malware.

Confidence: 64%Severity: 56%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:02 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Famrouter%2F@917b5376c5b6ffbeade177f8a09d8199956add4de3e193b19c3160f66125ef6b
Security Audit — socket — amrouter