hive-mcp
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core MCP setup is mostly coherent and routes credentials to Hive’s official endpoint, but risk is elevated by unpinned npx execution and especially the transitive skill-install step via a third-party skills CLI. This is not confirmed malware, but it has meaningful supply-chain and trust-chain risk beyond simple configuration guidance.
Confidence: 85%Severity: 56%
Audit Metadata