hevy

Pass

Audited by Socket on Feb 16, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Feb 16, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/jakubrohleder%2Fagent-toolkit%2Fhevy%2F@471996244d358dc7c6b022c671607b58265c0773