rollinggo-hotel-booking

Warn

Audited by Socket on Aug 29, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/install.py

No direct malware behaviors (e.g., exfiltration, backdoor installation, eval-based execution) are present in this fragment. However, it performs high-risk supply-chain actions: installs a global npm package using an unpinned '@latest' version (which may trigger install lifecycle scripts) and downloads a remote executable binary from GitHub Releases without any integrity verification, then marks it executable. These patterns warrant security review, pinning, and artifact verification.

Confidence: 72%Severity: 60%
Audit Metadata
Analyzed At
Aug 29, 2026, 07:06 AM
Package URL
pkg:socket/skills-sh/rollinggo-ai%2Frollinggo-hotel-skill-cn%2Frollinggo-hotel-booking%2F@cfe121be6a047004a06e4992efddcccb4c70b71576a7323fdc95bda27b7b8b4b
Security Audit — socket — rollinggo-hotel-booking