cohesivity

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a backend/gateway integration, but it has a broad operational footprint: local secret-file reading, remote installer execution, infrastructure provisioning, and centralized routing of application/provider data through Cohesivity. Same-org domains and explicit consent gates weigh against outright maliciousness, but the combination of supply-chain risk, credential handling, and intermediary data flows makes it medium-to-high security risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Aug 13, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/cohesivity-org%2Fcohesivity-skill%2Fcohesivity%2F@af72f42886d5c7173d1e93ca6b4db320ef8d32d19dc7c7bb04b819667337e5eb
Security Audit — socket — cohesivity