fintoio

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s stated purpose is Finto.io integration, but its actual operation depends on Membrane as a credential and API intermediary. The npm-installed CLI appears official and documented, so this is not strong malware evidence, but the indirect data flow and server-side credential handling make it a medium-risk skill that extends trust beyond Finto itself.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ffintoio%2F@5dbf7c0b8184590e6452333e1c049d2d6d5f6ec3