huly-assist

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities and required Huly credentials fit its project-management purpose, and no obvious third-party exfiltration endpoint is disclosed. However, install/execution trust is weak because the core huly executable is required but not sourced or verified in the skill, so users are asked to hand API credentials to an effectively unverifiable local tool. This is not confirmed malware, but it is high security risk due to opaque binary trust and real-world mutation capabilities.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/fioenix%2Fhuly-skill%2Fhuly-assist%2F@d79e41a30b69e0bdea623fe31840df2121495150