coassemble

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's business actions match its Coassemble purpose, and the CLI install path is reasonably legitimate via npm. The main concern is data-flow integrity: all Coassemble access is brokered through Membrane, an intermediary service requiring its own account and credential handling, which expands trust and exposes user data/operations beyond a direct official API integration.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 21, 2026, 12:08 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcoassemble%2F@4e2be85359d7981170c97dc5a5df90888aeb3ca2