hive-setup

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core install and registration steps are broadly aligned with a Hive setup skill, and the main package source appears legitimate. The main risk is that it automatically clones server-provided task content and executes `prepare.sh` plus dependency installs from that remote repo, creating a substantial remote-code-execution and supply-chain exposure that is larger than a simple setup helper.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 21, 2026, 12:18 AM
Package URL
pkg:socket/skills-sh/rllm-org%2Fhive%2Fhive-setup%2F@324b67c6d8a4b71a9d1f7d7fc1d5b036ee94ab2d