yuanbao

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is purpose-aligned and has no supply-chain or credential-harvesting indicators, but it grants the agent autonomous communication powers: normal replies become live group messages and the DM tool can privately message users with optional files. That creates high real-world action risk and reduced transparency, though not confirmed malware.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 27, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/NousResearch%2Fhermes-agent%2Fyuanbao%2F@cad44e06f87cdf9de936930c927f1ff269d4d7fa