celoxis

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches Celoxis integration, and the CLI source is official npm-scope tooling, but the skill introduces a third-party Membrane trust boundary for authentication and API access instead of direct Celoxis endpoints. Overall this is coherent but medium risk due to mutable CLI install and intermediary data flow.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fceloxis%2F@3dd833cb861f462ab9e51a8a50d79dd85a90d02a
Security Audit — socket — celoxis