agentar
Audited by Socket on Jul 7, 2026
2 alerts found:
SecurityAnomalySUSPICIOUS. The skill’s purpose is coherent, but its actual trust model is not: it installs an unverifiable CLI through a remote test-hosted shell script, then passes API credentials to that CLI. The same-org relationship for the parent domain is only partially supported and does not verify this specific test subdomain, installer, or package, so the supply-chain and credential-forwarding risks dominate.
No direct malicious behavior is evidenced in this documentation-only fragment. However, it instructs users to download and execute a remote installer script and to install a remote tarball, without showing checksum/signature verification or pinned provenance, which creates a significant supply-chain security exposure. To determine whether the package is actually malicious, the contents of the referenced install.sh and package.tgz must be reviewed (and ideally verified via trusted signatures/hashes).