comodo

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s high-level purpose is coherent, and the install path uses npm rather than an obviously malicious download chain. However, it is not a direct Comodo integration: authentication, credential storage, and data access are routed through Membrane as a third-party intermediary, and the CLI is run from unpinned `@latest` versions. That makes the skill proportionate but higher-trust than its description suggests.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcomodo%2F@a81de54f050bf83b568a82e1e91ac529c341ab32