codemagic

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based Codemagic wrapper, and the CLI install source appears official, but its actual footprint relies on a third-party intermediary for authentication, action generation, and all API traffic instead of direct Codemagic APIs. That broader trust model and mutable global CLI install create medium risk, though there is no strong evidence of malware or hidden exfiltration.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcodemagic%2F@ce682391d5a85e52a4e547244c18218feca4d233
Security Audit — socket — codemagic