gangtise-copilot

Warn

Audited by Socket on May 12, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
scripts/install_gangtise.sh

No overt malware logic is present in this installer wrapper; it mainly performs download, extraction, copying, and symlinking of skill bundles. However, it introduces significant supply-chain risk by installing remote ZIP content without cryptographic integrity/authenticity checks and extracting archives without script-enforced safety controls. Additionally, the --only value is not sanitized before being used in filesystem paths and symlink targets, which increases the risk of unintended filesystem targeting if an attacker can influence inputs. Treat as a security-sensitive installer and mitigate via artifact verification (e.g., signed bundles/checksums) and safer handling of user-controlled skill names and archive paths.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 01:53 AM
Package URL
pkg:socket/skills-sh/daymade%2Fclaude-code-skills%2Fgangtise-copilot%2F@12b0e349c3ba55f2c03a317fbacdb08a67a826eb