kvk

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core function is coherent as a KVK integration, and the CLI install path is reasonably legitimate via npm, but the skill materially shifts trust and data flow from official KVK APIs to Membrane as an intermediary. That makes it higher risk than a direct API integration, though not malicious based on the provided evidence.

Confidence: 86%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 12:04 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fkvk%2F@029f5fa53105ea629e6d8bf9e826343384287e8b