hermes-paperclip-adapter

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but its footprint is high-risk because it enables a continuously managed AI employee with broad terminal/file/web/browser capabilities, persistent memory, and comment-driven execution. Install sources look conventional, yet the combination of autonomous operation, external CLI delegation, credential use, and promptable task/comment inputs makes this a high-security-risk integration even without clear evidence of malware or deceptive exfiltration.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 17, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Fhermes-paperclip-adapter%2F@b3e693af39f6e169eb9ee929af57ecb85269ae48
Security Audit — socket — hermes-paperclip-adapter