melo

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overt malware, and it uses a plausibly official CLI from npm, but its footprint is inconsistent with its stated Melo purpose and it routes all interaction through Membrane as a third-party intermediary. The strongest concern is purpose mismatch plus indirect remote action generation/execution; overall this is a medium-risk skill rather than confirmed malicious content.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 21, 2026, 11:20 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmelo%2F@15a3a3e3c7a937b64c189dfdae2141fe80c770b2