cobalt-io

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's broad purpose mostly matches its capabilities, and the Membrane CLI appears to be an official same-ecosystem tool from npm. However, the skill routes Cobalt access and authentication through Membrane as an intermediary, uses mutable `@latest` execution, and cites a clearly inconsistent fake-looking Cobalt docs domain (`cobalt.foo`). This is not confirmed malware, but it has meaningful trust and data-flow risk disproportionate to a simple direct Cobalt integration.

Confidence: 89%Severity: 68%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcobalt-io%2F@49e6ef770d828d3b9fa24a621bde988bb0e218b9