kickfire

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose matches its capabilities, and the CLI source appears official, so this is not malware-like. However, the integration routes authentication and KickFire operations through Membrane as an intermediary platform, with mutable `@latest` CLI execution and server-side action generation, creating medium security risk and broader trust requirements than a direct KickFire integration.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 11:36 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkickfire%2F@5c0ba4550257756dbbbf5cf3e37abd3cbd3f0e98