hibob

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated HiBob integration purpose and uses a legitimate npm-distributed CLI, so it does not look malicious. However, all access is mediated through Membrane rather than direct HiBob APIs, the agent must trust a third-party CLI/service with authentication and HR data, and the skill enables high-impact HR actions; this makes it medium risk despite coherent purpose.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 09:42 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhibob%2F@76a6227b36d942d3d8a60fc4abef4144de4d4eed
Security Audit — socket — hibob