hydrogen
Warn
Audited by Socket on Apr 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The install path is mostly legitimate and same-org via npm, but the skill has a major purpose mismatch and routes authenticated requests through Membrane as an intermediary. The strongest concern is incoherence about what “Hydrogen” actually is, which undermines trust in the requested capabilities and data flows.
Confidence: 90%Severity: 61%
Audit Metadata