herobrine

Fail

Audited by Socket on Mar 18, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s behavior matches its stated purpose, but that purpose is inherently high risk because it grants a scheduled Claude instance broad autonomous execution with `--dangerously-skip-permissions`, optional outbound messaging, and the ability to process untrusted external content. Install trust is mostly coherent and same-org, so the main concern is autonomy and data-flow scope rather than malware-like deception.

Confidence: 90%Severity: 84%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/aaarnv%2Fclaude-skills%2Fherobrine%2F@bdfd1ffd351a367d5d1d3e32ecf0fd3f6d4a7960