kintone

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated Kintone purpose and the CLI comes from npm rather than a raw installer, so this is not overtly malicious. However, all authentication and Kintone access are routed through Membrane as a third-party intermediary instead of directly to official Kintone endpoints, and the agent is asked to trust a globally installed CLI plus backend service for credential handling and action generation. That makes the skill coherent but medium-risk from data-flow and delegated-trust perspectives.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Apr 23, 2026, 09:10 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkintone%2F@8375e69b8ae6cc5cd4e7f0bb98912ed60eaae2f4