cobalt

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s actual footprint is not fully consistent with its stated purpose. The install path is relatively normal (official npm package), but the skill routes authenticated Cobalt access through Membrane and the listed actions describe a different product domain than the support-ticket narrative. That combination makes the integration internally inconsistent and medium-high risk, though not confirmed malware.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcobalt%2F@c2d52e3f3db75fb9561edc4d1c27f2620d29895eaacbd770726da7ee825026ee
Security Audit — socket — cobalt