cobalt-io

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the overall workflow is mostly coherent for a Membrane integration skill, and the CLI install path appears same-product and registry-based rather than an unverifiable binary. However, the skill sends Cobalt access through Membrane as an intermediary, uses mutable CLI execution, and includes a false 'official docs' domain (`cobalt.foo`), creating meaningful trust and data-flow concerns inconsistent with a clean direct Cobalt integration.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcobalt-io%2F@1c2d1555d216607a20f68f3f890c4dea0c499ad7