halo

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible, but the execution model is not proportionate. A Halo management skill should call Halo’s official API directly or use an official Halo client; instead it mandates a third-party npm CLI and forwards HALO_PAT to it, creating high supply-chain and credential exposure risk.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 16, 2026, 11:21 AM
Package URL
pkg:socket/skills-sh/tnnevol%2Fskills%2Fhalo%2F@31b245afdf85e895b33b5d141e92616f812f7d38