cn-index

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is plausible, but it forces all requests through an unverifiable private API on a bare IP, embeds an API key in the skill, and sends that key over HTTP without TLS. The file-copy install is benign, but the actual data flow and credential handling are not trustworthy or proportionate.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
May 8, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/HubbleVision%2Fhubble-data-service-skill%2Fcn-index%2F@74e49ede074641686e18ecccf0c447193658ec72