openstoryline-install

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN. The skill’s capabilities match its stated purpose: local source installation, config editing, asset download, and localhost service startup. Main concern is supply-chain hygiene: required assets are pulled by same-project download.sh from an external cloud bucket without integrity verification. That is a meaningful security risk, but not evidence of credential theft, hidden exfiltration, or behavior disproportionate to the installation task.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Sep 17, 2026, 12:58 PM
Package URL
pkg:socket/skills-sh/fireredteam%2Ffirered-openstoryline%2Fopenstoryline-install%2F@8faabfa071be9144febe8abcd162315e26f0ecdae7db7eac7922aaae263bf37b
Security Audit — socket — openstoryline-install