create-pdf-fixture

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
run.sh

The script appears to be a development utility for generating PDF fixtures. It contains no direct indicators of malicious behavior, but it executes a remote Git repository through uv and sources a local .env file as shell code. Those operations create meaningful supply-chain and local-code-execution risks if the repository or .env file is compromised. Pinning the repository to a reviewed commit and avoiding executable environment-file sourcing would reduce risk.

Confidence: 96%Severity: 55%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:01 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fcreate-pdf-fixture%2F@3fceca0273529800604d89fad50537204dd3b1b0
Security Audit — socket — create-pdf-fixture