hostinger-headless
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
AnomalyAnomalyentry/skill.md
LOWAnomalyLOW
entry/skill.md
SUSPICIOUS: the skill's purpose broadly matches website setup on Hostinger, but its trust model is heavier than a simple bootstrap. Same-org GitHub sourcing reduces concern, yet the combination of raw-script download, unpinned `npx @latest` execution, and transitive skill installation makes the install path risky. No clear evidence of malware or credential exfiltration beyond Hostinger's own flow, but the skill should be treated as medium-high risk until package provenance and official docs alignment are clearer.
Confidence: 83%Severity: 68%
Audit Metadata