codeguard

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
install.sh

No direct malware or explicit data theft is visible in this bash installer fragment. However, it has significant supply-chain risk: it unconditionally clones and installs unpinned, unauthenticated remote repository content into a persistent application “skills” directory (likely later loaded/executed by the host), strips provenance metadata, and follows a risky remote execution distribution pattern. This should be reviewed with integrity/pinning and safer installation practices before use.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 10:27 PM
Package URL
pkg:socket/skills-sh/yousefabdallah171%2Fcode-quality-reviewer%2Fcodeguard%2F@b6ccf84d0cf4d60c649642597caa9b6d46a97982
Security Audit — socket — codeguard