monitor-herdr
Warn
Audited by Socket on Aug 26, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is largely coherent with its stated Herdr monitoring/orchestration purpose and uses mostly official/local interfaces, but it has a broad operational footprint: cron-based prompt injection, workspace-closing capability, transitive composition of other skills, and reliance on a third-party Herdr file-viewer plugin from an unrelated GitHub owner. I found no strong evidence of credential theft or deliberate exfiltration, so this is better classified as elevated security risk rather than malware.
Confidence: 84%Severity: 66%
Audit Metadata