cliniko
Warn
Audited by Socket on May 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities fit its purpose, and the CLI comes from an official npm package, so this is not overtly malicious. However, all Cliniko access and credentials are mediated by Membrane rather than direct official Cliniko APIs, which creates a meaningful third-party data-handling risk for sensitive healthcare records; combined with @latest global CLI install and partially unverified command details, this is better classified as suspicious than benign.
Confidence: 84%Severity: 58%
Audit Metadata