seed-hypermedia-read

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This SKILL document is a read-only gRPC usage guide for querying a local Seed Hypermedia server. It does not contain network calls to external attacker-controlled domains (other than suggesting the official GitHub releases page for grpcurl), does not request credentials, and explicitly forbids write/update/delete operations. The main security considerations are (1) the download-then-run guidance for grpcurl (standard but a supply-chain pattern), and (2) shell interpolation examples that can enable command injection if untrusted input is inserted without escaping. There is no evidence of obfuscation, credential harvesting, remote data exfiltration to external hosts, or embedded malicious payloads in the provided text. Overall the content appears benign for its stated purpose but carries modest operational risks typical of shell-based tooling and binary downloads.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 04:14 PM
Package URL
pkg:socket/skills-sh/seed-hypermedia%2Fseed%2Fseed-hypermedia-read%2F@4dbb028240e0bf33bee45625388861a88faab341