hostinger-headless

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
entry/skill.md

SUSPICIOUS: the skill's purpose broadly matches website setup on Hostinger, but its trust model is heavier than a simple bootstrap. Same-org GitHub sourcing reduces concern, yet the combination of raw-script download, unpinned `npx @latest` execution, and transitive skill installation makes the install path risky. No clear evidence of malware or credential exfiltration beyond Hostinger's own flow, but the skill should be treated as medium-high risk until package provenance and official docs alignment are clearer.

Confidence: 83%Severity: 68%
Audit Metadata
Analyzed At
Aug 28, 2026, 09:55 PM
Package URL
pkg:socket/skills-sh/hostinger%2Fapi-mcp-server%2Fhostinger-headless%2F@2884ad55617757be10976c2d975b8377692b77a1cdb6028b13031f5dd505edb3
Security Audit — socket — hostinger-headless