kandy

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is internally coherent for a Membrane-published Kandy integration, and the CLI install path is relatively trustworthy. However, all Kandy credentials and data are routed through Membrane's intermediary platform instead of official Kandy APIs, creating meaningful third-party credential and data-flow risk; combined with unpinned CLI installation and dynamic action creation, this makes the skill medium risk rather than benign.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Apr 30, 2026, 11:37 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkandy%2F@ce805d251c856e8f7829ab657e1219764dfaed94
Security Audit — socket — kandy