comeet

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent as a Membrane-based Comeet integration and uses an official-looking npm package, so it is not overtly malicious. Risk comes from routing sensitive recruiting data and auth through Membrane instead of direct Comeet APIs, plus an unpinned global CLI install and expanded third-party trust boundary.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Apr 30, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcomeet%2F@ba2006d031e95957738b5e89a5c034223c2e0402
Security Audit — socket — comeet