honey-px

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but its execution path is not fully trustworthy. The main concern is the npx-installed pxpipe-proxy package processing broad local content while the documentation names a different upstream tool, leaving install provenance and data handling unclear.

Confidence: 80%Severity: 58%
Audit Metadata
Analyzed At
Jul 7, 2026, 10:42 AM
Package URL
pkg:socket/skills-sh/Green-PT%2Fhoney-for-devs%2Fhoney-px%2F@f7ad60e57c91112c03655b5d8d8164ac42d1692832c0599266b321f94682d10b
Security Audit — socket — honey-px