codereadr

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent and uses an official registry install, but it routes CodeREADr authentication and API activity through Membrane rather than the official vendor API. That intermediary trust model is disclosed and plausible for a Membrane integration skill, so this is not confirmed malicious, but it carries moderate security risk due to third-party credential/data handling and an unpinned CLI install.

Confidence: 82%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 05:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcodereadr%2F@a49f2cedfff7c4f087435dc2354e8bed28117175
Security Audit — socket — codereadr