tianxiabachang-perspective

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
install.sh

No direct malicious behavior (e.g., credential theft, exfiltration, reverse shell, or runtime command execution) is evident in this installer script itself. The primary risk is supply-chain trust: it downloads an unpinned GitHub ZIP from a moving branch, extracts untrusted content, and installs entire skill directories wholesale into a persistent plugin/skills location with only a superficial SKILL.md existence check. If the upstream repository or transport is compromised, malicious skill content could be installed for later use by the host application. Backup/rotation operations are also potentially risky if unexpected symlinks or filesystem state exist.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
May 7, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/momozi1996%2Fawesome-ai-persona-skills%2Ftianxiabachang-perspective%2F@967511d8df9f896c2e4da9c780dc29163b035c4a
Security Audit — socket — tianxiabachang-perspective