hermes-labyrinth-observability

Warn

Audited by Socket on May 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The capability set mostly fits a Hermes observability plugin, and the documented data flows are local/read-only with redaction. The main concern is install trust: users are told to clone a personal GitHub plugin repo not clearly operated by the stated publisher or Hermes maintainers, with imperfect version-verification. This looks more like a third-party plugin with moderate supply-chain risk than overtly malicious behavior.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 17, 2026, 08:49 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-labyrinth-observability%2F@529107dab6b9e8b9eca4095ab55b9494400f0d68
Security Audit — socket — hermes-labyrinth-observability