algomo

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is documentation for integrating with Algomo via the Membrane CLI. There is no explicit malicious code or instructions to exfiltrate local secrets. The primary security considerations are supply-chain and privacy/trust: installing a third-party CLI from npm and routing all API calls and credential management through Membrane centralizes trust in that vendor. If Membrane is trustworthy and the @membranehq/cli package is secure, the skill's behavior is coherent with its stated purpose. Users and reviewers should vet the Membrane CLI package and the operator's privacy/security posture before granting it access to sensitive accounts or data.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falgomo%2F@b07b21ef2d04927c6a479c9b03b993c3f9a85438