zHive

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious but not malicious. The skill is broadly aligned with its stated zHive agent-management purpose, but it depends on an unpinned external CLI executed through Bash, includes transitive skill installation instructions, and can automate recurring/public posting behavior. The main concern is supply-chain and delegated-action risk rather than credential theft or clear exfiltration.

Confidence: 84%Severity: 66%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/zhive-org%2Fzhive%2Fzhive%2F@e66a7783544e7e5cd6c6235b65262ef6cc5497fb