pilvio

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Pilvio connector, and the CLI install source appears legitimate, but the core data path routes Pilvio access through Membrane rather than directly to official Pilvio APIs. That third-party mediation of authentication and action execution creates medium security risk and trust expansion, though there is not enough evidence to call it malicious.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fpilvio%2F@82f737110f96c5fd294a789dcfeb27aae9584823