hive
Audited by Socket on Mar 12, 2026
1 alert found:
Obfuscated FileThe skill appears to be a benign integration scaffold for Hive via the Membrane CLI. It relies on standard, trusted distribution (npm) for the CLI, uses browser-based authentication managed by Membrane, and routes Hive interactions through Membrane’s proxy with server-side credential handling. No explicit credential reads from local files, no download-execute chains beyond the initial CLI install, and data flows through official APIs. Overall risk is low-to-medium due to dependency on Membrane for credentials and proxy handling, but there are no obvious security holes given the described flow. Maintain awareness of Membrane’s security posture and ensure users trust Membrane as a credential manager and proxy.