chatwoot

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Chatwoot integration, and the CLI install source appears official, but it routes authentication and API access through Membrane instead of directly to Chatwoot. That extra intermediary and server-side credential handling make the scope and data flow moderately risky, though not clearly malicious.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Sep 29, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fchatwoot%2F@1b44279e5e8ca83a17c76fe983c6e2101116f55234d67511aef087332a3094b7
Security Audit — socket — chatwoot