install-moomoo-opend

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
scripts/install_win.md

The code is an installer helper with no direct evidence of malicious intent or data theft. However, it has meaningful security risk because it downloads mutable content from a remote endpoint, executes an unverified extracted executable, bypasses PowerShell execution policy, and forcefully deletes local files. Use only after independently verifying the download source, archive checksum, and executable signature; avoid running it unchanged on sensitive systems.

Confidence: 96%Severity: 68%
SecurityMEDIUM
scripts/install_mac.md

The fragment describes a plausible installer workflow and does not itself demonstrate malware or data theft. However, it has meaningful supply-chain security weaknesses: it downloads and installs unverified executable software, executes an unreviewed shell script, and explicitly disables Gatekeeper quarantine protection. The artifact should not be treated as trusted without validating publisher signatures, notarization, checksums, archive contents, and fixrun.sh. The code is not materially obfuscated, but the overall installation procedure presents a moderate security risk.

Confidence: 96%Severity: 70%
Audit Metadata
Analyzed At
Sep 20, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/moomooopen%2Fmoomoo-agent-hub%2Finstall-moomoo-opend%2F@bc6a782c7cedd0b302e37c55f84b9e801b204eb6317070115df4fca250035637
Security Audit — socket — install-moomoo-opend