tikoci-qemu-user-emulation

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
references/macos-vm-bridging.md

No direct malicious behavior is evident in this fragment itself; it is primarily infrastructure to boot a minimal Linux VM with bridged networking and a host-mounted 9p directory. However, it contains multiple high-impact trust and execution surfaces: it mounts host content with security_model=none and then executes a script directly from that mount (/host/.vm-cmd.sh). Additionally, it loads many kernel modules via insmod, making initramfs/module artifact integrity critical. Treat this as a potentially high security-risk design requiring strong provenance/integrity controls for downloaded boot artifacts and the host directory contents.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Jun 22, 2026, 05:00 PM
Package URL
pkg:socket/skills-sh/tikoci%2Fquickchr%2Ftikoci-qemu-user-emulation%2F@92b9b72b7e06153ab90dd074f9c1b4c74fbe0dd529cd689d067a4099fccacfbd
Security Audit — socket — tikoci-qemu-user-emulation