optimoroute
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's purpose and commands are mostly aligned, and the installer comes from an official registry, but all OptimoRoute access is mediated through Membrane rather than the official OptimoRoute API. That third-party proxy/auth model is explicitly disclosed, so this is not confirmed malware, but it creates medium security risk because credentials and business data transit an intermediary service outside the official vendor path.
Confidence: 88%Severity: 61%
Audit Metadata