coveralls
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the install path is legitimate, but the skill’s actual integration model routes Coveralls authentication and API traffic through Membrane infrastructure rather than directly to Coveralls. That extra intermediary is disproportionate for a simple Coveralls skill and creates meaningful credential and data-flow risk, though there is no clear evidence of malware or obfuscation.
Confidence: 88%Severity: 62%
Audit Metadata