kmsg

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install.sh

The script itself contains no obvious overt malware logic (no exfiltration, credential access, obfuscated execution, or additional persistence mechanisms beyond PATH editing). However, it creates a direct supply-chain execution path by downloading an unverified executable from a moving “releases/latest” endpoint and executing it immediately. The primary risk is integrity/authenticity of the downloaded binary; if the release artifact or redirect chain is compromised, the installer would run attacker-controlled code in the user context.

Confidence: 74%Severity: 64%
Audit Metadata
Analyzed At
Mar 29, 2026, 06:00 PM
Package URL
pkg:socket/skills-sh/jkf87%2Fopenclaw-kakao%2Fkmsg%2F@6275b2384b4c2f2e5e2cf9a8f982b31c730c0ac5
Security Audit — socket — kmsg