install-moomoo-opend

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install_mac.md

The fragment is a macOS installer workflow that performs high-impact actions (downloads an unverified remote tar.gz, extracts it, mounts a bundled DMG, copies a .app into /Applications, removes Gatekeeper quarantine, and launches it). The primary supply-chain risks are missing integrity verification and explicit Gatekeeper bypass, which significantly increase the consequences if the downloaded artifact or redirect is tampered with. No direct signs of credential theft, data exfiltration, or backdoor logic are visible in this snippet, but the workflow’s trust model is inherently sensitive due to unverified remote execution and optional execution of a bundled script.

Confidence: 62%Severity: 63%
Audit Metadata
Analyzed At
May 13, 2026, 11:14 AM
Package URL
pkg:socket/skills-sh/MoomooOpen%2Fmoomoo-agent-hub%2Finstall-moomoo-opend%2F@5e268b7ca2ef2df12b034d03e703c1acdbbb1b1e