hevy

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is coherent, and the visible data flow is plausibly to official Hevy services, but its core capability depends on an undocumented bundled binary. Because that executable is unverifiable and it receives the user's Hevy API key, the main risk is supply-chain trust and credential forwarding rather than confirmed malicious behavior.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:28 PM
Package URL
pkg:socket/skills-sh/jakubrohleder%2Fagent-toolkit%2Fhevy%2F@963a961d9d85413fc46242c00745f4ae916ea09d