ht-scan-project

Warn

Audited by Socket on Jun 18, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
SKILL.md

SUSPICIOUS. The core project-scanning behavior is mostly aligned with the stated purpose and data flows are limited, but the skill overclaims privacy by saying everything is 100% local while it fetches remote data, and the surrounding HackerTrip install/distribution model appears to use a same-domain curl|bash path without strong public release verification. I see no evidence of credential harvesting or code upload, so this is not malicious, but it carries medium trust and transparency risk.

Confidence: 83%Severity: 56%
AnomalyLOW
README.md

No malicious functionality is directly evidenced in the provided fragment (it is primarily README/usage text). However, the installation approach executes a remotely fetched script via a curl|bash pattern with no visible integrity verification, which is a significant supply-chain risk. The scanner’s claimed “local-only” operation and whether it transmits any scan-derived metadata cannot be confirmed without reviewing the actual install.sh and scanner source code.

Confidence: 52%Severity: 65%
AnomalyLOW
install.sh

This Bash fragment is not a direct malware dropper by itself (it does not execute or exfiltrate data), but it creates a meaningful supply-chain risk by downloading unpinned, unsigned “skill” content from a mutable remote GitHub raw URL and wiring it into multiple AI assistant skill directories via symlinks. If the upstream content (or transport) is compromised, downstream tools could be induced to process attacker-controlled instructions or data. The optional dataset download failure handling and the “100% local” claim are not technically enforced in this installer.

Confidence: 72%Severity: 61%
Audit Metadata
Analyzed At
Jun 18, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/Jayden72Huang%2Fhacker_trip%2Fht-scan-project%2F@387ffde56d553612620ac0f1b6e07130e42875581f819028977ef440da1b9edb
Security Audit — socket — ht-scan-project