linux-server-provisioning
Audited by Socket on Oct 6, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core host-configuration behavior fits a Linux provisioning skill, and most package/config access is proportionate. However, the footprint is widened by raw root-level installers, transitive installation of another skills repo plus helper execution, and a default full web stack that exceeds a minimal baseline unless explicitly approved.
No explicit malicious payload is visible in the provided fragment (no clear backdoor/reverse shell/obfuscated code/exfil logic), but the script performs several high-risk supply-chain actions: executing remote installer/bootstrap scripts as root (`curl ... | sudo bash` / `curl ... | sudo -E bash -`) and cloning/executing an unspecified Git repository (`linux-skills`) and wiring its scripts into `/usr/local/bin`. These patterns can enable sabotage or malware insertion if upstream content is compromised or not pinned/verified. Treat this as elevated supply-chain risk rather than confirmed malware.