hermes-in-buzz

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/update_buzz_credentials.py

No clear in-module malware/backdoor/obfuscated payload is present. However, the module has a significant supply-chain/execution trust risk: it runs external executables specified by the caller (--helper and --buzz) and sends sensitive keys/owners to the helper via stdin. If those binaries are malicious or substituted, secrets can be exfiltrated. The rest of the code mainly performs input validation, parses/updates a .env file, and runs subprocesses with derived environment variables.

Confidence: 72%Severity: 55%
Audit Metadata
Analyzed At
Aug 13, 2026, 02:22 PM
Package URL
pkg:socket/skills-sh/tonbistudio%2Fbuzz-skills%2Fhermes-in-buzz%2F@e6422b873cf42c935b0012cd6bdfb2af019b98da4d0a4b8028e8adcd6ad04df3
Security Audit — socket — hermes-in-buzz