ghost-scan-deps

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Security
SecurityMEDIUM
agents/init/agent.md

The supplied content is an installation instruction, not the installer source itself. It uses the high-risk `curl | bash` pattern against a mutable GitHub branch, allowing remote code to execute and install or replace binaries without demonstrated cryptographic verification. No confirmed malware is visible from the instruction alone, but the installer should be reviewed and pinned to a trusted commit with verified signatures or checksums before use.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 29, 2026, 05:27 AM
Package URL
pkg:socket/skills-sh/ghostsecurity%2Fskills%2Fghost-scan-deps%2F@04e92d2a4a7219063f5651f70b3e324e474c2908404b6764780188c5f8862b35
Security Audit — socket — ghost-scan-deps