blackbox

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core behavior matches its stated purpose, and its install sources appear consistent with the Blackbox CLI ecosystem, so this is not clearly malicious. However, it delegates code and repository context to a third-party agent service, forwards an API credential to external CLI code, and includes workflows that analyze untrusted PR content with write/exec capability plus optional auto-approval. The main concern is elevated operational and data-handling risk rather than clear credential theft or hidden exfiltration.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:51 PM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fblackbox%2F@dd69a31951363e0d313a7a402f67a4258110a059