kodagpt

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-hosted integration and uses an official npm-distributed CLI, so there is no strong evidence of malware. However, it routes KodaGPT access and authentication through Membrane as an intermediary rather than clearly using official KodaGPT APIs directly, creating moderate data-flow and credential-forwarding risk. Overall this looks like a legitimate connector skill with medium trust concerns, not confirmed malicious behavior.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:55 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkodagpt%2F@f5cbbec2159ecb6bc2bcfbfb702dae4e0e3e9f9c