companycam
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is mostly coherent as a Membrane-based CompanyCam integration and uses an official npm-distributed CLI, so there is no strong evidence of malware. However, all authentication and API traffic are funneled through Membrane as an intermediary rather than directly to CompanyCam, and the documented scope is unusually overbroad for the stated purpose. This makes it higher-trust and medium-risk, but not malicious on the supplied evidence.
Confidence: 86%Severity: 51%
Audit Metadata