kodagpt

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is mostly coherent as a Membrane-hosted integration and uses an official npm-distributed CLI, so there is no strong evidence of malware. However, it routes KodaGPT access and authentication through Membrane as an intermediary rather than clearly using official KodaGPT APIs directly, creating moderate data-flow and credential-forwarding risk. Overall this looks like a legitimate connector skill with medium trust concerns, not confirmed malicious behavior.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 07:10 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkodagpt%2F@43068a0a40330ccd535961ad985c51cc7e0b5ef3
Security Audit — socket — kodagpt