seed-hypermedia-read
Audited by Socket on Feb 27, 2026
1 alert found:
MalwareThis SKILL document is a read-only gRPC usage guide for querying a local Seed Hypermedia server. It does not contain network calls to external attacker-controlled domains (other than suggesting the official GitHub releases page for grpcurl), does not request credentials, and explicitly forbids write/update/delete operations. The main security considerations are (1) the download-then-run guidance for grpcurl (standard but a supply-chain pattern), and (2) shell interpolation examples that can enable command injection if untrusted input is inserted without escaping. There is no evidence of obfuscation, credential harvesting, remote data exfiltration to external hosts, or embedded malicious payloads in the provided text. Overall the content appears benign for its stated purpose but carries modest operational risks typical of shell-based tooling and binary downloads.