hevy

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK skill. Its stated purpose fits Hevy workout management, and the documented API domains are coherent with Hevy, but the required `hevy` CLI is an undocumented, unverifiable binary that receives the user's Hevy API key. Under the mandatory scoring rules, that combination warrants high security risk and elevated malware probability despite no confirmed malicious endpoint or payload.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:28 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fhevy%2F@cc473618e4a51d699e15d138fe827b828294f6a1
Security Audit — socket — hevy