hotjar

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's actions fit Hotjar access, and the CLI install path looks legitimate, but the core data flow is routed through Membrane rather than directly to Hotjar. That third-party mediation of authentication, request proxying, and data access makes the skill higher risk than its stated Hotjar-only purpose suggests.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 4, 2026, 11:16 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhotjar%2F@e45fa55ac5f55eb02125b9c31e73482590b0989e