buddy
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The install path is largely legitimate and same-ecosystem, but the skill is internally inconsistent: it claims Buddy CI/CD integration while describing unrelated record types, and it routes all Buddy access through Membrane rather than directly to official Buddy endpoints. This looks more like a generic Membrane wrapper than a tightly scoped Buddy skill. Not confirmed malware, but medium risk due to third-party credential/data mediation and purpose-capability mismatch.
Confidence: 86%Severity: 58%
Audit Metadata