Linux Production Shell Scripts

Warn

Audited by Socket on May 12, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible SKILL.md is broadly consistent with a Linux shell scripting guide and shows no direct credential theft or exfiltration, but its scope stretches into security/pentest use and the install ecosystem relies on remote skill-fetch channels, including some third-party ZIP distribution with weak provenance. Main concern is supply-chain and partially hidden sub-skill scope, not confirmed malicious behavior.

Confidence: 100%Severity: 60%
AnomalyLOW
sub-skills/phase-10-git-and-development.md

No explicit malware (no credential theft, exfiltration, persistence, or obfuscation) is evident in the provided fragment. However, it contains two high-impact operations: (1) unpinned `git fetch/pull` that blindly integrates upstream branch content into local repositories, and (2) direct arbitrary remote code execution by streaming a caller-specified local script into `bash -s` over SSH with no allowlisting or script integrity verification. This should be treated as a security-sensitive tool that must tightly control inputs, hosts, and script provenance.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 01:45 PM
Package URL
pkg:socket/skills-sh/Dokhacgiakhoa%2Fantigravity-ide%2Flinux-production-shell-scripts%2F@a7d78e02d7a29f054bcefc984eadf34e4be37bab
Security Audit — socket — Linux Production Shell Scripts