peaka

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the npm-installed Membrane CLI appears to be a legitimate first-party tool, so this is not strong evidence of malware. However, the skill’s actual footprint is mediated entirely through Membrane rather than direct Peaka APIs, and the Peaka-specific description/object model appears inconsistent with the claimed cloud-spend-management purpose. That combination makes the skill internally questionable and medium risk.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:02 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpeaka%2F@0e55063f22c510766a63c1121c5cacc69ea87fd5