avochato

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is not overt malware, but it is a medium-risk third-party proxy integration. Its purpose is coherent at a high level, yet the actual footprint relies on Membrane as an intermediary for authentication, data access, and action execution instead of using Avochato's official API directly. That extra trust boundary and the ability to perform outbound messaging make it suspicious enough to warrant caution.

Confidence: 88%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:12 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Favochato%2F@a81095abf147d96305330895770abdb833af1665
Security Audit — socket — avochato