covalent

Pass

Audited by Socket on Mar 12, 2026

Checks
Malicious behaviorInjection, exfiltration, untrusted installs
Security concernsCredential exposure, tool/trust exploitation
Code obfuscationHidden or obfuscated code
Suspicious patternsReconnaissance, excessive autonomy, resource use
Audit Metadata
Analyzed At
Mar 12, 2026, 11:27 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcovalent%2F@87d0a7e9c843af28cabbc0cf332a918dc07cb439