0codekit

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior is coherent with its stated purpose, and its install path uses an official npm package rather than an unverifiable binary. However, it routes access through Membrane as an intermediary, uses a mutable global CLI install, and enables broad remote action execution against many data types, so the overall risk is medium rather than benign.

Confidence: 82%Severity: 51%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:13 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F0codekit%2F@265954c53cc207aaafee0fc9fa80a3bbebd03107
Security Audit — socket — 0codekit