hyprland
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityinstall.sh
MEDIUMSecurityMEDIUM
install.sh
Overall, the module is a git-based installer that introduces a major supply-chain execution risk by sourcing a repository-controlled file (.wiki-version) into the current shell during installation/update, without any integrity/pinning verification of fetched content. While the snippet itself does not visibly implement malware/exfiltration, it can enable arbitrary command execution if the upstream repository (or that specific file) is compromised. Additionally, the rm -rf "$TARGET" behavior increases blast radius if TARGET can be influenced outside expected directories.
Confidence: 72%Severity: 78%
Audit Metadata