code-climate

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the install source is mostly legitimate, but the skill's core design routes Code Climate authentication and API traffic through Membrane as a third-party intermediary. That is misaligned with a straightforward service integration and creates meaningful credential-handling and data-flow risk even without clear evidence of malware.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:39 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcode-climate%2F@ead78e268c4c180f00e85561db8f43eafe31f2e9
Security Audit — socket — code-climate