gang

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose matches its behavior, but its actual footprint depends almost entirely on an external `hive` CLI installed from an unpinned personal GitHub repo, and that CLI then performs broader orchestration and downstream skill handoff. This is not enough to call malicious, but the install trust and delegated control make it medium risk.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/notdp%2Fhive%2Fgang%2F@4e845ff782b3c74ce5894e9af56532451f45db0e