cronofy

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, and the install source is an official npm package tied to the stated publisher ecosystem, so this is not strong evidence of malware. However, all Cronofy access is routed through Membrane rather than official Cronofy APIs, the CLI is installed unpinned at `@latest`, and authenticated calendar data/operations depend on a third-party mediation layer with logging/credential handling on that platform. This is a legitimate-looking integration with medium security risk due to intermediary data flow and delegated credential handling, not confirmed malicious behavior.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcronofy%2F@386bdec24155e3d92b34c7a2349dd7b7ddabcb1e
Security Audit — socket — cronofy