kommo

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated Kommo integration purpose and uses an official-looking vendor CLI from npm, so it is not overtly malicious. However, it routes authentication and API traffic through Membrane rather than directly to Kommo, and uses floating CLI versions, creating medium trust and data-flow risk that exceeds a simple direct API integration.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkommo%2F@c4b8b31d5986c0fa42227cd66a0f9ee896f8357e
Security Audit — socket — kommo