klaro-app

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's overall purpose is coherent, and the install source is an official npm package tied to the stated publisher, so this is not strong evidence of malware. However, all Klaro access is mediated through Membrane's CLI and proxy rather than direct Klaro APIs, creating meaningful third-party trust and data-flow risk, especially with unpinned CLI installs.

Confidence: 84%Severity: 54%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fklaro-app%2F@06a66de1be5f76747605fe6c39575840ff522b5b
Security Audit — socket — klaro-app