leadoku

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior is mostly coherent for a CRM integration, and the CLI comes from an official npm package, so this is not confirmed malware. However, all Leadoku access is mediated through Membrane rather than direct official APIs, creating third-party credential/data routing, and the documentation contains a notable mismatch (HubSpot docs in a Leadoku skill).

Confidence: 84%Severity: 55%
Audit Metadata
Analyzed At
May 1, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fleadoku%2F@0b3e0233f2da71d1cf3160537e464b9c2093b984
Security Audit — socket — leadoku