hot-monitor

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Hot Monitor skill presents a coherent, scope-appropriate tool for discovering and reporting trending topics across multiple public sources using local scripts and optional API access. Its footprint—pip-based dependencies from official registries, no embedded unverifiable binaries, and credential exposure limited to an optional Twitter API key—aligns with its stated purpose. Data flows are straightforward: user intent drives script-driven data collection from public sources, followed by local analysis and user-facing reports. Overall risk is low-to-moderate (securityRisk ~0.25–0.35) and malware risk is negligible, with no evident credential harvesting or covert data exfiltration patterns identified.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 12:13 PM
Package URL
pkg:socket/skills-sh/liyupi%2Fyupi-hot-monitor%2Fhot-monitor%2F@beb22ebd0cdf96db101794adbab5bcb411569061