hive-create-task

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core scaffolding and GitHub publishing are broadly aligned with its purpose, but it creates and executes local shell scripts and, more importantly, forwards an admin key to an unverified Hive CLI for public upload. Because an unverifiable CLI receives credentials, this meets the mandatory high-risk floor even without proof of malicious intent.

Confidence: 86%Severity: 84%
Audit Metadata
Analyzed At
Apr 5, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/rllm-org%2Fhive%2Fhive-create-task%2F@ff1e96d3ff909c21ebadcf311ab26f9467735939