fetcher
Audited by Socket on Aug 26, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS: the core fetching behavior fits the stated purpose, but the trust model is weak because it auto-installs and runs unpinned code from a personal GitHub repo via uvx. Credential use is mostly proportionate, yet forwarding secrets into Git-sourced tool code and fetching arbitrary web content create medium-high security risk even without clear malicious intent.
No direct malware such as credential exfiltration, reverse shells, cryptomining, destructive operations, or suspicious outbound destinations is present in the wrapper itself. The principal security issue is arbitrary code execution from any discovered .env file because those files are sourced as shell scripts. The script also trusts and executes a remote GitHub package and downloads browser binaries, creating supply-chain and network trust risks. Review or harden the repository, restrict .env locations and permissions, and parse dotenv files without executing them.