cliniko

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its purpose, and the CLI comes from an official npm package, so this is not overtly malicious. However, all Cliniko access and credentials are mediated by Membrane rather than direct official Cliniko APIs, which creates a meaningful third-party data-handling risk for sensitive healthcare records; combined with @latest global CLI install and partially unverified command details, this is better classified as suspicious than benign.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 2, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcliniko%2F@8d8f0da62182d1565c114c85b824319fd575aae0
Security Audit — socket — cliniko