hk
Warn
Audited by Socket on Feb 27, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The fragment is a coherent, legitimate setup/documentation guide for hk and its workflow. It does not contain executable payloads or embedded secrets. The primary security considerations arise from the described ability to download binaries from remote sources and to rewrite git hook paths, which could be abused if the remote release is compromised or if a user blindly trusts an unverified binary. Overall, the content is benign in intent but carries standard supply-chain risk exposure due to remote binary installation and hooks manipulation; treat as suspicious-prone rather than malicious until code is inspected or provenance is verified.
Confidence: 75%Severity: 75%
Audit Metadata