hermes-desktop-companion

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities largely match its stated desktop-companion purpose, but its trust model is weak and broad: unsigned binaries, security-control bypass instructions, same-org-unpinned installer usage, third-party skill installation, many credential types, and autonomous outbound messaging. This looks more like a high-risk agent control plane than clear malware, but the scope and supply-chain posture are disproportionate enough to treat as suspicious.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 17, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-desktop-companion%2F@c65fc7864571b023c760c9f0c557367db11ca557
Security Audit — socket — hermes-desktop-companion