cacoo

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core function is coherent, but it does not directly integrate with Cacoo; instead it requires a Membrane account, installs the Membrane CLI, and routes authentication and app interactions through Membrane as an intermediary. That expanded trust boundary and mutable CLI execution make it medium risk, though not malicious based on the provided evidence.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 09:06 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcacoo%2F@7c83c34675b3fec6dd77fc9e17bf6add2edb35a5