coda

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is Coda integration, but the actual model is a Membrane-mediated proxy that handles authentication, stores connection credentials, and routes data/actions through a third-party service. Install trust is relatively normal via npm, but the credential and data-flow scope is broader than a direct Coda skill and is the main risk driver.

Confidence: 88%Severity: 68%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:11 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcoda%2F@b3634a4f68c699d1f4d5fa1de9de05f350255529
Security Audit — socket — coda