cockroachdb
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly coherent as a Membrane-based CockroachDB integration, but its real footprint is wider than the title implies because all auth and data access are mediated through Membrane and it supports arbitrary proxied requests. Install trust is moderate rather than high-risk because the CLI comes from npm, but `@latest`/`npx` keep the execution path mutable.
Confidence: 82%Severity: 52%
Audit Metadata