hevy
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK skill. Its stated purpose fits Hevy workout management, and the documented API domains are coherent with Hevy, but the required `hevy` CLI is an undocumented, unverifiable binary that receives the user's Hevy API key. Under the mandatory scoring rules, that combination warrants high security risk and elevated malware probability despite no confirmed malicious endpoint or payload.
Confidence: 89%Severity: 84%
Audit Metadata