inedo-otter

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches Otter management, and the CLI install path is legitimate npm-based same-vendor tooling. However, authentication, credential storage, and API traffic are routed through Membrane rather than directly to official Inedo Otter APIs, creating a meaningful third-party credential and data-brokerage risk. This looks more like a managed integration gateway than malware, but the intermediary data flow and broad proxy access make it medium risk.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:56 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Finedo-otter%2F@c8360b0341c5b1fc9f40292298e1c3240e7b48eb