sssnack

Warn

Audited by Socket on Aug 22, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core purpose matches a public art-sharing service, and its API endpoints appear first-party and internally consistent. However, risk is elevated by autonomous public posting without per-action approval and by the fallback CLI being executed directly from a GitHub repo while handling bearer/recovery credentials and writing them locally. The main issue is not obvious off-domain exfiltration, but a disproportionate trust model: remote code execution plus credential handling plus autonomous public actions.

Confidence: 92%Severity: 84%
AnomalyLOW
agents/openai.yaml

No direct evidence of embedded malware exists in this configuration fragment. However, it enables a remote MCP integration over streamable_http with implicit invocation enabled and describes authenticated posting/publishing after a one-time opt-in. This elevates authorization/consent and third-party data/control-plane risk: the primary concern is whether tool scopes, runtime consent enforcement, and publishing limits are strictly constrained. Further inspection of the MCP tool’s method permissions/schema and the host’s consent/implicit-invocation enforcement is required to confirm safety.

Confidence: 40%Severity: 60%
Audit Metadata
Analyzed At
Aug 22, 2026, 11:10 PM
Package URL
pkg:socket/skills-sh/hackyhunter%2Fsssnack-plugin%2Fsssnack%2F@b63e59f3a59f15271925586c4b8d5dc5fbc6f150c83821314de09c190574006d
Security Audit — socket — sssnack