hive-setup
Warn
Audited by Socket on Mar 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core install and registration steps are broadly aligned with a Hive setup skill, and the main package source appears legitimate. The main risk is that it automatically clones server-provided task content and executes `prepare.sh` plus dependency installs from that remote repo, creating a substantial remote-code-execution and supply-chain exposure that is larger than a simple setup helper.
Confidence: 85%Severity: 74%
Audit Metadata