minecraft-modpack-server

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent for Minecraft server setup, but its install path is too trusting: it fetches a server pack from an arbitrary URL and runs included scripts without verification. There is no clear credential theft or off-purpose data exfiltration, so this is not confirmed malware, but the remote download-and-execute pattern plus system-level changes make it high security risk.

Confidence: 89%Severity: 82%
Audit Metadata
Analyzed At
Apr 27, 2026, 07:09 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fminecraft-modpack-server%2F@64a228ef190a50aac2f5ca0e455f0a9eb3ef93a5