hashnode
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's blog-management purpose is coherent, but it achieves it by routing full-account session cookies into a local helper and relying on an internal Hashnode API plus a third-party reconnect domain. The main concern is disproportionate credential sensitivity and weaker trust/data-flow integrity than Hashnode's official PAT/GraphQL path, not confirmed malware.
Confidence: 88%Severity: 72%
Audit Metadata