dromo

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent as a Membrane-hosted Dromo integration and uses an official npm-distributed CLI, but it introduces a third-party trust boundary: authenticated Dromo access and API traffic are routed through Membrane infrastructure instead of directly to Dromo. That is not outright malicious, but it is a meaningful data-flow and credential-handling risk compared with a direct Dromo integration.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Apr 24, 2026, 04:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fdromo%2F@7d632c6b007d3b8f8ac336e27d4178da725eff1e