hermes-web-ui-dashboard

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with a Hermes administration dashboard, but its footprint is high-impact and the install trust is weaker than the branding suggests. Main concerns are unpinned curl/bash setup, unclear publisher-to-package relationship, personal Docker namespace, and the dashboard’s broad access to credentials, terminal, files, SSH/container backends, and scheduled actions. Data flows appear mostly local or to official provider endpoints rather than an obvious credential-harvesting proxy, so this is not confirmed malware.

Confidence: 89%Severity: 69%
Audit Metadata
Analyzed At
May 19, 2026, 04:50 AM
Package URL
pkg:socket/skills-sh/aradotso%2Fhermes-skills%2Fhermes-web-ui-dashboard%2F@56d4f0f469cfdf6c9875653a95dd79e8a703c22e
Security Audit — socket — hermes-web-ui-dashboard