animade

Warn

Audited by Socket on Sep 13, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/bootstrap.mjs

This is an automated remote bootstrapper with a significant supply-chain security risk. It contacts a third-party default domain, globally installs an npm package, and executes the resulting CLI. The package metadata is partially validated, but ANIMADE_CLI_PACKAGE bypasses that validation. The fragment does not itself demonstrate malware, data theft, or sabotage, but compromise or untrustworthiness of the origin, npm package, dependencies, or overridden executable could lead to arbitrary code execution with user privileges. Review the domain, package provenance, integrity/signature controls, and whether the environment overrides are trusted before use.

Confidence: 97%Severity: 82%
Audit Metadata
Analyzed At
Sep 13, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/xue-xiaobao%2Fanimade-skill%2Fanimade%2F@44455917463b8ee7067f0448c65399eaed61eb21
Security Audit — socket — animade