code-climate
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the install source is mostly legitimate, but the skill's core design routes Code Climate authentication and API traffic through Membrane as a third-party intermediary. That is misaligned with a straightforward service integration and creates meaningful credential-handling and data-flow risk even without clear evidence of malware.
Confidence: 88%Severity: 76%
Audit Metadata