tolgee

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities match Tolgee management, and its install source is a legitimate npm package from the same vendor ecosystem, so this is not overt malware. However, it shifts all Tolgee access and authentication through Membrane instead of Tolgee’s direct API flow, creating notable credential-forwarding and intermediary data-flow risk that is broader than a simple Tolgee integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftolgee%2F@ee39c161f7468611a6dc99890431f64d8a9bf659