cradl-ai

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is coherent, and the CLI install source appears legitimate via npm, but the integration routes Cradl authentication and API traffic through Membrane as a third-party intermediary instead of directly to official Cradl endpoints. That makes the main risk data-flow and credential forwarding through a proxy service, not overt malware or an obviously malicious installer.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcradl-ai%2F@891b8d6d7b94579d0cd2b146d1d19a191148138d