shell-integration
Audited by Socket on Sep 15, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill’s purpose and capabilities mostly align as a shell-integration reference, and most scanner hits are documentation artifacts. However, its install/distribution guidance includes downloading and executing an unverifiable placeholder binary, then eval/source of shell code emitted by that binary, which creates a disproportionate supply-chain risk for a documentation skill even without evidence of active malware or exfiltration.
No direct malicious behavior is evident in the supplied fragment. It describes conventional shell-plugin integration, but it carries a meaningful supply-chain and shell-code execution risk: an unverified binary from a mutable latest-release URL is executed, and its output is repeatedly evaluated or sourced. Pin releases, verify signatures or checksums, minimize eval usage, and protect cached/configuration files before using this pattern in production.