hono

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is largely a benign Hono framework reference and its main `npx hono request` usage aligns with official tooling, but the added recommendation to use unverified `workers-fetch` introduces disproportionate supply-chain risk inconsistent with otherwise official guidance. No confirmed malware or credential theft behavior is present.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Sep 17, 2026, 11:21 PM
Package URL
pkg:socket/skills-sh/midudev%2Fautoskills%2Fhono%2F@bb82a810caeff5d64eb87cfe341f206db26c7601bcb3364a1313a5b2cc4bf4ff
Security Audit — socket — hono