ifood

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally consistent as a Membrane-based integration, and the CLI source appears legitimate via official npm. However, it materially changes the trust model by routing iFood authentication, credentials, and API traffic through Membrane's service and proxy instead of direct official iFood API access. Combined with unpinned @latest CLI execution, this makes it medium-risk and suspicious rather than benign.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fifood%2F@788d497f3b54b8413f64c1a826ffb24e74a4aee1
Security Audit — socket — ifood