powershell-security-hardening
Warn
Audited by Socket on Sep 23, 2026
1 alert found:
AnomalyAnomalyreferences/signing_guide.md
LOWAnomalyLOW
references/signing_guide.md
The fragment is legitimate code-signing guidance and does not show clear malicious behavior. It contains several security weaknesses: a hardcoded plaintext certificate password, potentially unprotected private-key backup, insecure HTTP timestamp URLs, and an optional bypass for unsigned-script execution. These issues warrant remediation before operational use, but the provided code does not indicate malware or a supply-chain backdoor.
Confidence: 98%Severity: 58%
Audit Metadata