cloudflare-tunnel-publish

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_tunnel.sh

No clear indicators of overt malware are present in the provided script fragment. The security risk is primarily supply-chain and operational security: it downloads and executes a mutable “latest” release without integrity verification, and it passes a sensitive run_token via command-line arguments. Additionally, if the $WORKSPACE/bin directory is writable by an attacker, the script could execute a swapped binary. Overall: moderate risk due to weak authenticity/integrity controls rather than confirmed malicious payload behavior.

Confidence: 74%Severity: 66%
Audit Metadata
Analyzed At
May 9, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcloudflare-tunnel-publish%2F@b4db6859be3a6272a04643e091bb383aaa3ac00d