ringover
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities broadly match its stated Ringover-integration purpose, and the CLI install source is an official npm package from the same vendor ecosystem. However, all authentication and API traffic are funneled through Membrane rather than directly to Ringover, creating an intermediary data/credential path that is broader than a direct Ringover integration and should be treated as medium risk rather than benign.
Confidence: 85%Severity: 56%
Audit Metadata