kingsumo

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly consistent with its stated purpose as a Membrane-based KingSumo integration, and the CLI install source appears official and verifiable. The main risk is architectural: authentication, credentials, and KingSumo data are routed through Membrane as an intermediary rather than directly to KingSumo, plus the CLI is installed via unpinned `@latest`. This is not strong evidence of malware, but it is a moderate-trust integration pattern with third-party credential/data handling.

Confidence: 85%Severity: 52%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkingsumo%2F@cd8bd3bc94d3db5c8ff7e0886f4869d0f3474151
Security Audit — socket — kingsumo