awesome-hermes-agent-ecosystem

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is ecosystem guidance, but the skill goes beyond reference material by encouraging extensive installation of third-party skills and tools from many unrelated GitHub owners, plus broad credential setup and autonomous workflows. I do not see confirmed malware or overt exfiltration, but the transitive trust chain and disproportionate operational footprint make this a high security-risk skill.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
May 17, 2026, 12:29 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fai-agent-skills%2Fawesome-hermes-agent-ecosystem%2F@636af544c18ca6d45d740527de50288e1faa4f0f
Security Audit — socket — awesome-hermes-agent-ecosystem