cumulio

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its Cumul.io workflow, and the install path uses an official npm package from the same vendor ecosystem, so this is not overt malware. However, the integration is mediated through Membrane rather than direct Cumul.io APIs, requiring users to trust a third-party CLI/service with authentication, connection management, and action execution; combined with mutable `@latest` installation, this makes the skill medium risk rather than benign.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 08:36 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fcumulio%2F@828798c537dbee874e4f218a4b4ef16344d5ed3e
Security Audit — socket — cumulio