codemagic
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent as a Membrane-based Codemagic wrapper, and the CLI install source appears official, but its actual footprint relies on a third-party intermediary for authentication, action generation, and all API traffic instead of direct Codemagic APIs. That broader trust model and mutable global CLI install create medium risk, though there is no strong evidence of malware or hidden exfiltration.
Confidence: 87%Severity: 58%
Audit Metadata