kickfire

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches its capabilities, and the CLI source appears official, so this is not malware-like. However, the integration routes authentication and KickFire operations through Membrane as an intermediary platform, with mutable `@latest` CLI execution and server-side action generation, creating medium security risk and broader trust requirements than a direct KickFire integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 04:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkickfire%2F@5706c23950e351d75531116c064bf214779aef5c