cliengo

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated Cliengo-integration purpose and uses an official npm-distributed Membrane CLI, so this is not confirmed malware. The main risk is architectural: it routes authentication and Cliengo operations through Membrane as a third-party intermediary, and it enables real external actions plus dynamic action creation. That makes it medium risk and suitable only when the user explicitly intends to trust Membrane as the control plane for Cliengo.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcliengo%2F@5272d32b59219948c11ba98931901135d0a72b56
Security Audit — socket — cliengo