openhanako-personal-ai-agent

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally consistent as documentation for a highly autonomous desktop agent platform, but the platform's footprint is inherently high-risk: it combines web ingestion, file/terminal/JS execution, scheduling, messaging bridges, and third-party skill installation. The main installer path appears same-project and documented, so this is not confirmed malware, but transitive GitHub skill installs and broad autonomous host access materially elevate security risk.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/reason-machines%2Ftrending-skills%2Fopenhanako-personal-ai-agent%2F@7dcb958089b2aa016d6cbfadae2fffeb43f7ba75437f002a35c163fd6060c01e
Security Audit — socket — openhanako-personal-ai-agent