ax

Warn

Audited by Socket on Jul 27, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/setup.sh

No explicit backdoor, credential theft, or exfiltration is present in this script fragment. However, it performs high-impact supply-chain actions: it can execute a remotely fetched installer script directly via `curl -fsSL ... | bash` with an environment-overridable URL and without integrity verification, and it downloads/enables an executable without checksum/signature checks. Treat this as potentially dangerous in adversarial environments unless the install endpoint and inputs are tightly controlled (e.g., pinned, integrity-verified, and not environment-manipulable).

Confidence: 72%Severity: 76%
Audit Metadata
Analyzed At
Jul 27, 2026, 11:40 AM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fax%2F@9e595041f66ad6a8124e139985d69d794b9e9d048a6f7230040418dee818db98
Security Audit — socket — ax