kagi-search

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
kagi-search.sh

Best report: Report 3 is the closest overall to a correct assessment, and it correctly identifies the key supply-chain risks in this wrapper. Improved findings: (1) the script executes a downloaded binary from an unpinned upstream 'releases/latest' tag (artifact can change), (2) checksum verification is conditional and can be skipped entirely when the checksum entry is missing, and (3) execution occurs via exec "$BIN" with no sandbox. There is no direct evidence of embedded malware in the shell code itself; the security risk is primarily that this bootstrapper can become an arbitrary-code-execution vector if upstream artifacts or checksums are compromised or if the checksum lookup fails.

Confidence: 67%Severity: 64%
Audit Metadata
Analyzed At
Mar 27, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/joelazar%2Fkagi-skills%2Fkagi-search%2F@b224bb450589215a8a02b3f5e6e5bc927294e400