albato

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is a documentation/integration wrapper instructing users to use the official Membrane CLI to access Albato. The capabilities described align with the stated purpose. The primary security consideration is centralized trust: users must trust the @membranehq/cli npm package and Membrane's proxy service because request bodies and credentials are handled by Membrane rather than the client directly. There are no apparent covert exfiltration attempts, hardcoded secrets, download-and-execute chains, or obfuscated/malicious code in the supplied text. Recommend vetting the @membranehq npm package publisher, using a scoped package checksum or pinned version where possible, and being aware that proxied requests and credentials transit Membrane's infrastructure.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falbato%2F@7f8b12fdf8d487fc60ed9dfaa69f7126b44ee57c