i18n-setup

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
evals/run-layer-b.sh

This is an orchestration script with notable supply-chain and execution-control risks rather than clear, explicit malware code in the snippet. The script performs runtime network fetches (git clone and npm install) and then runs a Claude agent with --dangerously-skip-permissions, which weakens safety boundaries; the prompt is only advisory. If any fetched dependency/skill/fixture is malicious (or if install hooks execute unexpected actions), the script could facilitate unauthorized file/network/process actions during the agent run. No hardcoded secrets or explicit exfiltration destinations are present in this fragment.

Confidence: 68%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 04:40 PM
Package URL
pkg:socket/skills-sh/crowdin%2Fskills%2Fi18n-setup%2F@c5e85c33bd980448e4dd2dfbaf13703d422592b04e98c891d0fbf1199069eb46
Security Audit — socket — i18n-setup