commbox

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is plausible, and the CLI comes from an official npm package tied to the publisher, so this is not clear malware. However, the core design routes CommBox authentication and API traffic through Membrane as an intermediary rather than using CommBox's official direct API flow, creating a meaningful data-flow and trust-boundary concern. Medium overall risk.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcommbox%2F@3d85890599f39236b749b586ab362fac96b39ac1
Security Audit — socket — commbox