llm-as-computer

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
src/setup.sh

No direct malicious code is evident in this shell fragment. However, it performs high-impact supply-chain actions by installing Mojo toolchain components (`modular`, `mojo`, `max`) into the host’s system Python environment at runtime using `--system --break-system-packages`, without visible version pinning or artifact integrity verification, and then immediately executes the installed toolchain to build a binary from a locally trusted-but-unaudited `executor.mojo`. Treat this primarily as a toolchain/build-supply-chain risk and verify pinning + integrity controls, and ensure `executor.mojo` is trusted and protected from tampering.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
May 7, 2026, 04:35 AM
Package URL
pkg:socket/skills-sh/oaustegard%2Fclaude-skills%2Fllm-as-computer%2F@61f0d742bb49abd6466acf86ee27a3691ed10bb2