carbone
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent as a Carbone integration guide, and the CLI install path appears legitimate, but its actual data flow depends on Membrane as a credential-managing proxy rather than direct Carbone API access. That intermediary routing is the main risk and makes the footprint broader than the stated purpose implies.
Confidence: 83%Severity: 62%
Audit Metadata