automox

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill description is coherent with its stated purpose: it provides a legitimate workflow to integrate Automox through the Membrane CLI, with server-managed credentials and proxy-based API access. No hardcoded secrets or suspicious data flows are evident, and network interactions rely on trusted registries and Membrane-managed authentication. The pattern of using a proxy for API calls is acceptable when credentials are centrally managed. Overall, the fragment appears benign and proportionate to its purpose, with no clear malicious indicators.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:58 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fautomox%2F@36924295380c4dcfe028a78e3e62dafcb44259df