nixos

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Security
SecurityMEDIUM
install.sh

This is a git-based installer/updater that fetches remote repository content without pinning or integrity verification and then executes repository-provided shell code via source "$TARGET/references/.wiki-version" when present. That makes the primary risk a supply-chain execution pathway (arbitrary command execution under the user’s privileges). Additionally, it can delete directories with rm -rf "$TARGET" where TARGET can be influenced by invocation, increasing the chance of destructive misuse or unintended deletion.

Confidence: 76%Severity: 78%
Audit Metadata
Analyzed At
Jul 24, 2026, 01:56 PM
Package URL
pkg:socket/skills-sh/marceloeatworld%2Fnixos-ai-skill%2Fnixos%2F@5f8b9dbfdb549567bb572952ba249a37f11bc16c
Security Audit — socket — nixos