sherlock

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally consistent and uses official install sources, with no credential harvesting or hidden exfiltration, so it is not malware-like. However, its stated purpose is active OSINT/reconnaissance against many social platforms, which is a high-misuse security capability for an AI agent and warrants elevated risk despite otherwise coherent design.

Confidence: 90%Severity: 61%
Audit Metadata
Analyzed At
Apr 4, 2026, 05:52 PM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fsherlock%2F@21f61186b2f9a6ac059ecaf69fec06d15de3041b