pinecone
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileThe Pinecone skill aligns with its described purpose: it uses Membrane as the authentication and proxy layer to interact with Pinecone, avoiding local exposure of credentials and leveraging official registries for installation. Data flows through Membrane to Pinecone with server-managed credentials, which is appropriate for a developer tooling integration. Overall, the footprint is coherent with a legitimate integration tool; no direct credential harvesting, unsanctioned network exfiltration, or hostile behavior is evident. Some risk remains around how credentials are managed by Membrane and how proxy requests are authenticated, but these are design expectations of the Membrane platform rather than suspicious behavior within this skill itself.