hyperstack-consume
Warn
Audited by Socket on Feb 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
This skill is coherent with its stated purpose (reading and streaming Hyperstack data). I found no embedded malware, download-and-execute constructs, hardcoded secrets, or instructions to harvest local credentials. The main security considerations are normal for a streaming SDK: (1) do not connect to untrusted wss:// URLs without verifying the endpoint, (2) be cautious with console logging of entity data that may contain sensitive fields, and (3) be aware of supply-chain risk when installing npm/cargo packages. Overall risk is moderate but expected for a networked SDK; no malicious behavior is evident in the provided content.
Confidence: 75%Severity: 50%
Audit Metadata