hive-mcp

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core MCP setup is mostly coherent and routes credentials to Hive’s official endpoint, but risk is elevated by unpinned npx execution and especially the transitive skill-install step via a third-party skills CLI. This is not confirmed malware, but it has meaningful supply-chain and trust-chain risk beyond simple configuration guidance.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Jul 24, 2026, 12:29 AM
Package URL
pkg:socket/skills-sh/hive-intel%2Fhive-skills%2Fhive-mcp%2F@17a298fcf4950a0f100143bab0806ddb83f1dbfadd9214f98b066356c470056a
Security Audit — socket — hive-mcp