formaloo
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill is broadly coherent for a Formaloo integration, and its CLI comes from an official registry rather than an obviously malicious source. The main risk is that all authentication and API traffic are funneled through Membrane as an intermediary, plus unpinned `@latest` execution, which raises medium trust and data-flow concerns but does not by itself show malicious intent.
Confidence: 86%Severity: 57%
Audit Metadata