carto

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's broad Carto-management purpose mostly matches its capabilities, and installation comes from the official npm registry rather than an unknown binary. However, all Carto interaction is funneled through Membrane as an intermediary service, expanding data exposure and trust beyond Carto itself, and the install/run path uses unpinned `@latest` CLI execution.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 12:19 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcarto%2F@4b7f1a4c26312631f7daa9dd675992888feeecb8
Security Audit — socket — carto