hyros

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based Hyros integration, and the CLI install path is reasonably trustworthy via npm. However, it materially reroutes Hyros authentication and API traffic through Membrane rather than official direct Hyros API calls, expanding trust and enabling proxy-mediated access to sensitive analytics and account actions. This is not confirmed malicious, but the intermediary data flow and real-world write capabilities raise medium risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:57 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhyros%2F@10dca874a6584ba50fde0618101496d0774adc49