od-contribute

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
install.sh

No direct malware or explicit exfiltration/backdoor behavior is present in this installer fragment. However, it is a high-impact supply-chain installer: it fetches and installs remote repository content without any cryptographic integrity/authenticity verification, allows user-controlled branch selection, and preserves a credential-like .gh-token across reinstalls. If the upstream repository/branch (or the served tarball contents) is compromised, this script can propagate malicious agent skill/command content into the user’s agent environments with persistent token availability.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Fod-contribute%2F@e45a2bd3f58824033fc8571eb39a659dcb649f58c533f66a35680f6cb1a46a1e
Security Audit — socket — od-contribute