ecologi

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, and the CLI install source appears official, but the integration is mediated through Membrane rather than direct Ecologi endpoints, so credentials and data are entrusted to a third-party platform. The presence of purchase actions adds real-world action risk. Not malware, but medium security risk due to third-party credential routing, mutable CLI install, and transaction capability.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fecologi%2F@c91b870d6c481bbdc47eb20464313849a65a5307