hh-mcp

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and API scope are broadly coherent for an hh.ru MCP integration, and the install path uses official tooling and PyPI rather than an arbitrary downloader. However, it forwards a powerful hh.ru token to a third-party MCP package from a personal publisher, not official HeadHunter tooling, while enabling write and irreversible employer actions. This is not confirmed malware, but it is a meaningful trust and credential-handling risk.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 11, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/ilyautov%2Fhh-mcp-ru%2Fhh-mcp%2F@1abe80b943b50bd35494e59ec0ac02ed86a639d3076ce6c0b7b8467d2315e371
Security Audit — socket — hh-mcp