hypermoji

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its commands, and it avoids direct credential scraping, but it delegates authenticated operations to an external CLI whose publisher/provenance was not clearly verifiable from public evidence. Main risk is supply-chain and credential trust in the CLI rather than overtly malicious behavior in the skill text.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Mar 22, 2026, 12:20 AM
Package URL
pkg:socket/skills-sh/hypersocialinc%2Fhypermoji-skills%2Fhypermoji%2F@d4c93ba91564f60e4e7c597c275df21a2b6120c3