cincopa

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is purpose-aligned and uses an official npm-distributed CLI from the same vendor named in the documentation, so it does not look malicious. The main risk is architectural: it routes Cincopa operations and authentication through Membrane as an intermediary proxy rather than directly to official Cincopa endpoints, creating moderate trust, credential-forwarding, and data-flow risk. Overall classification: SUSPICIOUS due to third-party mediation, but not malware.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 11:49 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcincopa%2F@0d04d5fd317b5852ac2b621101eb64d90354db1b