kommo

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated purpose is Kommo integration, but it requires a separate Membrane account and routes authentication, credentials, and CRM operations through Membrane rather than Kommo's official API directly. The install source is relatively legitimate (official npm package), so this is not confirmed malware, but the third-party credential/data mediation makes the skill materially higher risk than a direct Kommo integration.

Confidence: 89%Severity: 77%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:42 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkommo%2F@9717ae6485a34a0b71301c1578fa651b2fc9897d