huly-api

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core purpose matches Huly collaboration, but it grants an agent broad autonomous publishing behavior, forwards raw bearer tokens to a runtime-configured backend, and lets untrusted channel content influence later actions. No clear malware or hostile installer is present, yet the combination of token handling, configurable endpoints, and mandatory cross-surface posting creates meaningful security risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 23, 2026, 01:28 PM
Package URL
pkg:socket/skills-sh/proompteng%2Flab%2Fhuly-api%2F@b87c4ca08f3c6681a4463c525b738a929a21088f