klaro-app
Warn
Audited by Socket on Apr 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's overall purpose is coherent, and the install source is an official npm package tied to the stated publisher, so this is not strong evidence of malware. However, all Klaro access is mediated through Membrane's CLI and proxy rather than direct Klaro APIs, creating meaningful third-party trust and data-flow risk, especially with unpinned CLI installs.
Confidence: 84%Severity: 54%
Audit Metadata