cli-forge-publish

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/scripts/install-current-release.sh

No direct indicators of intentional malware are present in this Bash installer helper. The primary risks are supply-chain and trust-model issues inherent to installing a network-downloaded binary: the download origin can be redirected via GITHUB_REPOSITORY, and checksum verification is based on a checksum retrieved from the same release source with no independent signature/anchoring. Additionally, remote tar extraction is performed without explicit hardening/validation of archive contents. Overall: likely legitimate, but it should only be used with trusted config/release/tag and in controlled environments.

Confidence: 70%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:48 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fcli-forge%2Fcli-forge-publish%2F@14c26bce235c66e6e1ed2e6248392a5044af88c3
Security Audit — socket — cli-forge-publish