kintone

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities fit its stated Kintone purpose and the CLI comes from npm rather than a raw installer, so this is not overtly malicious. However, all authentication and Kintone access are routed through Membrane as a third-party intermediary instead of directly to official Kintone endpoints, and the agent is asked to trust a globally installed CLI plus backend service for credential handling and action generation. That makes the skill coherent but medium-risk from data-flow and delegated-trust perspectives.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
May 5, 2026, 07:04 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkintone%2F@1a5d461aab563bfdd14349c1a297ada04eab6458