outpost
Audited by Socket on Mar 1, 2026
1 alert found:
MalwareThe provided fragment is a high-level product manifest and installation guidance for Hookdeck Outpost, describing supported destinations and a self-hosted option. There are no executable code paths, no credential handling, and no data exfiltration observed within the fragment itself. The presence of an installation command (npx skills add ...) and references to external repositories means that, if used, a downstream module could install and configure components that interact with user destinations. However, as presented, the footprint is coherent with a legitimate product description and standard OSS distribution patterns. The primary risk vector is the implied ability to install and run additional skills that may perform networked deliverability tasks; this warrants review of the actual agent-skills integration and any permissions granted during installation. Overall risk is low based on the fragment alone, but attention should be paid to any downstream behavior when these skills are actually installed and executed in a user's environment.