herobot-chatbot-marketing
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is internally coherent as a Membrane-powered HeroBot integration, and the install path is from an official registry. However, it routes authentication and all HeroBot operations through Membrane rather than directly to HeroBot’s official API, creating a meaningful third-party trust and data-flow risk. Overall this is better classified as suspicious/medium risk than malicious.
Confidence: 85%Severity: 58%
Audit Metadata