ax

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/setup.sh

No explicit backdoor, credential theft, or exfiltration is present in this script fragment. However, it performs high-impact supply-chain actions: it can execute a remotely fetched installer script directly via `curl -fsSL ... | bash` with an environment-overridable URL and without integrity verification, and it downloads/enables an executable without checksum/signature checks. Treat this as potentially dangerous in adversarial environments unless the install endpoint and inputs are tightly controlled (e.g., pinned, integrity-verified, and not environment-manipulable).

Confidence: 72%Severity: 76%
Audit Metadata
Analyzed At
Sep 15, 2026, 06:04 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fax%2F@7f6f36a76dd93e0533f7318dd6b04471b45c82c93ae963378711be86aa798204
Security Audit — socket — ax