hokodo

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-based Hokodo integration, and its CLI install path is from an official registry. The main concern is data-flow integrity: Hokodo access is mediated through Membrane's hosted CLI/proxy service, creating a third-party trust boundary for credentials and API traffic that goes beyond a direct Hokodo integration. Not malicious, but medium risk due to intermediary routing and external service dependence.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
Apr 21, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fhokodo%2F@7b478c09de70b145c9c26cecabdd45b22d4529de