hermai-contribute
Warn
Audited by Socket on Apr 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Suspicious due to transitive skill installation and dynamic npx-based fetching, but not malicious on its face. The file is internally consistent as a deprecation notice; the main risk is asking the agent to trust and install another external skill.
Confidence: 87%Severity: 53%
Audit Metadata