hivo-drop

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The operational scope matches a storage skill, but it relies on an externally trusted `hivo` CLI and identity flow that could not be publicly verified from the provided evidence. Since that CLI receives authentication material and performs networked file operations, the main risk is unverifiable credential-bearing third-party tooling rather than confirmed malicious behavior in this skill text.

Confidence: 84%Severity: 83%
Audit Metadata
Analyzed At
Apr 10, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/zhiyuzi%2FHivo%2Fhivo-drop%2F@83210dca5dc9185a639ff065e326645ef1775037