cognito

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align, and installation uses a normal npm package rather than an opaque binary. However, all Cognito authentication and API traffic are mediated by Membrane rather than going directly to AWS, creating a third-party credential/data handling boundary, and the CLI install examples are unpinned. This looks like a legitimate integration pattern with medium trust and data-flow risk, not confirmed malware.

Confidence: 85%Severity: 53%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcognito%2F@5f02ff37a5ba75a71c86b254424d1fed2ac6a048