1kosmos-blockid

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based 1Kosmos integration guide, and its install path uses an official npm package rather than a raw downloader. However, it routes authentication and API traffic through Membrane instead of directly to 1Kosmos, creating a moderate third-party credential/data mediation risk; the unpinned `@latest` CLI install adds minor supply-chain risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F1kosmos-blockid%2F@2959fc8a5c443e4f59338e2cc027e373d2d8d244