melo
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is not overt malware, and it uses a plausibly official CLI from npm, but its footprint is inconsistent with its stated Melo purpose and it routes all interaction through Membrane as a third-party intermediary. The strongest concern is purpose mismatch plus indirect remote action generation/execution; overall this is a medium-risk skill rather than confirmed malicious content.
Confidence: 87%Severity: 58%
Audit Metadata