albato
Audited by Socket on Mar 4, 2026
1 alert found:
SecurityThe skill is a documentation/integration wrapper instructing users to use the official Membrane CLI to access Albato. The capabilities described align with the stated purpose. The primary security consideration is centralized trust: users must trust the @membranehq/cli npm package and Membrane's proxy service because request bodies and credentials are handled by Membrane rather than the client directly. There are no apparent covert exfiltration attempts, hardcoded secrets, download-and-execute chains, or obfuscated/malicious code in the supplied text. Recommend vetting the @membranehq npm package publisher, using a scoped package checksum or pinned version where possible, and being aware that proxied requests and credentials transit Membrane's infrastructure.