truora

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-hosted Truora connector, but its real footprint is broader than a plain Truora integration because all authentication and API activity are mediated by Membrane rather than going to Truora directly. The npm install source is comparatively legitimate, so this is not confirmed malware, but the third-party credential/data routing and unpinned CLI raise medium security concerns.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 10:05 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftruora%2F@90be771ed1c83f32958db7abf72cf3163d8af00e