apollo

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is coherent for a Membrane-hosted Apollo integration, and the CLI comes from an official npm package, so this is not confirmed malware. However, the skill routes Apollo authentication and API traffic through Membrane instead of using Apollo's official API directly, adding a meaningful third-party credential/data broker layer; combined with unpinned CLI execution and documentation inconsistencies, this warrants medium risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapollo%2F@bbb541860606ebca7fd060621f05f2c7de093816