robocorp

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The install path is mostly benign and vendor-consistent, but the skill's actual integration is not a direct Robocorp client. It requires a separate Membrane account, forwards authentication through Membrane, and proxies Robocorp API traffic through Membrane infrastructure, creating an intermediary trust and data exposure layer that is broader than the stated purpose.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 21, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frobocorp%2F@92b19011ac5ac44f1569a1eabf7bf2f2d5476b01