code42

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's overall purpose matches its capabilities, and the CLI comes from an official registry package linked to the same product ecosystem, so this is not confirmed malicious. However, all Code42 access and authentication are routed through Membrane as a third-party intermediary, and the install path uses unpinned `@latest`/`npx` execution; that makes the skill medium risk despite otherwise coherent documentation.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Apr 22, 2026, 06:54 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcode42%2F@cd56c49156ab465444d8ed1a58ca555ec9c471fd