algomo

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md is documentation for integrating with Algomo via the Membrane CLI. There is no explicit malicious code or instructions to exfiltrate local secrets. The primary security considerations are supply-chain and privacy/trust: installing a third-party CLI from npm and routing all API calls and credential management through Membrane centralizes trust in that vendor. If Membrane is trustworthy and the @membranehq/cli package is secure, the skill's behavior is coherent with its stated purpose. Users and reviewers should vet the Membrane CLI package and the operator's privacy/security posture before granting it access to sensitive accounts or data.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falgomo%2F@b07b21ef2d04927c6a479c9b03b993c3f9a85438
Security Audit — socket — algomo