kobo-auth
Warn
Audited by Socket on Jun 17, 2026
2 alerts found:
AnomalySecurityAnomalyscripts/kobo_install.sh
LOWAnomalyLOW
scripts/kobo_install.sh
This module primarily performs a supply-chain sensitive operation: it downloads and immediately executes an external macOS binary from a mutable 'releases/latest' endpoint (and can be redirected via --url) with only a weak size heuristic and no cryptographic verification. It also clears macOS quarantine, further reducing user/system safety signals. No explicit malware behaviors (e.g., exfiltration, backdoor commands) are evident in the fragment, but the integrity-validation gap makes the overall security posture meaningfully risky.
Confidence: 100%Severity: 60%
SecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Audit Metadata