oh-my-hermes-workflow

Warn

Audited by Socket on May 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches a DevOps automation skill, but the actual footprint is very broad and the installation trust is poor: a branded ara.so/Hermes workflow is installed by executing a mutable raw script from an unrelated personal GitHub repo. The skill also centralizes many high-value credentials and enables autonomous repo/deployment actions, so the scope and credential exposure are high relative to the unverifiable install path.

Confidence: 89%Severity: 88%
Audit Metadata
Analyzed At
May 16, 2026, 08:48 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fhermes-skills%2Foh-my-hermes-workflow%2F@2069af559f34052833ba8b6873a48a51683ec52e
Security Audit — socket — oh-my-hermes-workflow