hk-connect

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches market-data retrieval, but the actual footprint routes all data through a private raw-IP service over plaintext HTTP and forwards an API key there. The local install is harmless, yet the network trust model, hard-coded credential example, and non-TLS data flow make the skill medium-high risk.

Confidence: 91%Severity: 79%
Audit Metadata
Analyzed At
May 8, 2026, 02:52 PM
Package URL
pkg:socket/skills-sh/HubbleVision%2Fhubble-data-service-skill%2Fhk-connect%2F@84ddd2bff7dc80224e5a534dca35545640cdacab