byted-emr-skills

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/bin/install_serverless_sdk.sh

The script is simple but leverages a local wheel for installation, which introduces supply-chain and runtime risks. The absence of integrity checks, lack of input/path validation, and a potentially misnamed wheel file increase risk of inadvertent or malicious installations. This pattern is acceptable only with strong provenance controls and isolated builds.

Confidence: 59%Severity: 60%
Audit Metadata
Analyzed At
May 7, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/volcengine%2Fagentkit-samples%2Fbyted-emr-skills%2F@9a5ee6d93fb76d9a16f7bf3e8ea795767331038a