remote-package-installer
Warn
Audited by Socket on Sep 9, 2026
2 alerts found:
Securityx2SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally consistent, but its whole purpose is to fetch and install an unverifiable remote Python wheel from a non-real domain with no integrity checks. This is a high supply-chain risk even without evidence of credential theft or other malicious behavior.
Confidence: 97%Severity: 90%
Securityinstall.sh
MEDIUMSecurityMEDIUM
install.sh
The command itself does not demonstrate malware, but it attempts to install an unverified remote wheel from an invalid-looking domain. The actual wheel contents are unavailable, so malicious behavior cannot be ruled out. Treat this installation as unsafe and require a trusted source, integrity hash or signature, and package inspection before use.
Confidence: 98%Severity: 82%
Audit Metadata