bmad

Warn

Audited by Socket on Jul 28, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/install.sh

This fragment contains no overt malicious behaviors such as credential theft, exfiltration, or backdoor logic within the shown code. However, it has significant supply-chain risk because it performs direct remote code execution (`curl ... | sh`) to install an external CLI, and then executes additional local hook/init scripts without integrity verification in this fragment. The primary danger is that the remotely executed installer and/or the subsequently executed hook/init scripts could be compromised or malicious.

Confidence: 62%Severity: 70%
Audit Metadata
Analyzed At
Jul 28, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fbmad%2F@56e8cb55afd342fb45cb78fab0724e72611413e4cc1032b2700a36adf9e13acc
Security Audit — socket — bmad