zHive
Warn
Audited by Socket on Apr 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Suspicious but not malicious. The skill is broadly aligned with its stated zHive agent-management purpose, but it depends on an unpinned external CLI executed through Bash, includes transitive skill installation instructions, and can automate recurring/public posting behavior. The main concern is supply-chain and delegated-action risk rather than credential theft or clear exfiltration.
Confidence: 84%Severity: 66%
Audit Metadata