1kosmos-blockid
Warn
Audited by Socket on May 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is internally coherent as a Membrane-based 1Kosmos integration guide, and its install path uses an official npm package rather than a raw downloader. However, it routes authentication and API traffic through Membrane instead of directly to 1Kosmos, creating a moderate third-party credential/data mediation risk; the unpinned `@latest` CLI install adds minor supply-chain risk.
Confidence: 87%Severity: 56%
Audit Metadata