local-action-verification

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/install-act.sh

The visible code is a conventional convenience installer, but it has a significant supply-chain security weakness: it executes the latest unpinned remote install.sh directly with bash, potentially as root. Use a pinned release or commit, verify checksums or signatures, and review the installer before execution. No direct evidence of malware or data theft appears in the supplied fragment.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:26 PM
Package URL
pkg:socket/skills-sh/google-labs-code%2Fjules-skills%2Flocal-action-verification%2F@be46f4cbd7508379d7d1cea44bed5a7dd78f32a9297ec50676c2339d7cef6e8a
Security Audit — socket — local-action-verification