byted-emr-skills
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalyscripts/bin/install_serverless_sdk.sh
LOWAnomalyLOW
scripts/bin/install_serverless_sdk.sh
The script is simple but leverages a local wheel for installation, which introduces supply-chain and runtime risks. The absence of integrity checks, lack of input/path validation, and a potentially misnamed wheel file increase risk of inadvertent or malicious installations. This pattern is acceptable only with strong provenance controls and isolated builds.
Confidence: 59%Severity: 60%
Audit Metadata