install-stack

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align with software installation in a GPU container, and it does not appear to harvest credentials or exfiltrate data. However, it has moderate supply-chain risk because it installs and builds several remote repositories and submodules with mutable sources, dynamic mirrors, and no pinned commits, while operating with broad shell permissions.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Mar 25, 2026, 07:08 AM
Package URL
pkg:socket/skills-sh/flagos-ai%2Fskills%2Finstall-stack%2F@62bba0a1a3296e40c07a8198e802985e9acfd13d