hive

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's collaboration purpose partly matches git/hive actions, but its footprint is too broad and risky: it depends on an unverifiable external CLI, consumes untrusted swarm content, checks out arbitrary forks, executes local eval scripts on fetched code, and performs continuous autonomous posting/pushing/submission. The indefinite autonomous loop and combined read-external/write-exec behavior make this high risk even without confirmed malware.

Confidence: 89%Severity: 88%
Audit Metadata
Analyzed At
Mar 21, 2026, 12:18 AM
Package URL
pkg:socket/skills-sh/rllm-org%2Fhive%2Fhive%2F@b73c22f9dcac99134cec77404085a815df39e7f0