install-futu-opend

Warn

Audited by Socket on Sep 16, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/install_win.md

The code is an automated downloader, extractor, and installer launcher. It does not itself show clear malware behavior, but it presents a meaningful supply-chain risk because it executes an unverified executable fetched from a mutable remote endpoint, uses ExecutionPolicy Bypass, and performs forceful recursive cleanup. Verify the publisher signature and a release checksum before execution, and restrict cleanup paths before using this procedure.

Confidence: 97%Severity: 63%
AnomalyLOW
scripts/install_mac.md

The supplied content is an installer procedure, not evidence of malware by itself. It performs ordinary download, extraction, DMG installation, and cleanup operations, but it disables Gatekeeper quarantine and executes an unreviewed downloaded fixrun.sh script without integrity verification. The procedure should be treated as security-sensitive until the archive, DMG, application signature, and script are independently verified. The cleanup wildcard also warrants caution.

Confidence: 97%Severity: 63%
Audit Metadata
Analyzed At
Sep 16, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/futunnopen%2Ffutu-agent-hub%2Finstall-futu-opend%2F@1561b870f0b132d1cb0608a0ec58f86a19fba4649edff45439cc8b80efc7257b
Security Audit — socket — install-futu-opend