cometly

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI comes from an official registry, but all authentication and API traffic are funneled through Membrane instead of directly to Cometly. That third-party credential/data mediation is disclosed and plausibly integral to the product, so this is not malicious, but it creates medium security risk and elevated trust requirements.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcometly%2F@d306bf61630ede23bffbf8836ea968dd6a5ebba5
Security Audit — socket — cometly