cody

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly consistent with an integration purpose, but it routes Cody access through Membrane instead of an official Cody toolchain, creating an intermediary trust and data-flow boundary. The npm install source is legitimate and not inherently malicious, so this is not confirmed malware, but the third-party CLI, delegated auth, and mutable install make it a medium-risk skill.

Confidence: 83%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:16 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcody%2F@c8242a9eaaec8ba6210228c887ce398cd7540491