hivo-salon

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functionality is broadly aligned with salon collaboration, but it delegates all privileged actions and token handling to an unverifiable `hivo` CLI with no documented install provenance or public release trail in the evidence provided. No clear malicious exfiltration is shown, yet the black-box executable and cross-skill dependency make the overall security risk high.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
Apr 10, 2026, 04:36 AM
Package URL
pkg:socket/skills-sh/zhiyuzi%2FHivo%2Fhivo-salon%2F@293eaf946a96c0396c6ba0e71fa02c3af836e6d4