ecologi

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches its capabilities, and the CLI install source appears official, but all authentication and API traffic are funneled through Membrane rather than directly to Ecologi. That third-party mediation, combined with purchase-capable actions, makes the skill higher risk than a direct API integration even though there is no clear evidence of malware.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 23, 2026, 03:02 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fecologi%2F@07818c8c2ef7fcbb40df233ed98c78d943830e80