hive

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill appears to be a benign integration scaffold for Hive via the Membrane CLI. It relies on standard, trusted distribution (npm) for the CLI, uses browser-based authentication managed by Membrane, and routes Hive interactions through Membrane’s proxy with server-side credential handling. No explicit credential reads from local files, no download-execute chains beyond the initial CLI install, and data flows through official APIs. Overall risk is low-to-medium due to dependency on Membrane for credentials and proxy handling, but there are no obvious security holes given the described flow. Maintain awareness of Membrane’s security posture and ensure users trust Membrane as a credential manager and proxy.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 08:25 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhive%2F@c861f2a99d1936b7549d80bcbbb1e0d969654abe