mboum

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities broadly match an Mboum integration, but it routes authentication and operations through Membrane rather than directly to Mboum, while the target app’s purpose is described as unknown. The npm-installed CLI appears officially documented, so this is not confirmed malware, but the third-party mediation, broad action execution, and unpinned CLI make the skill medium risk.

Confidence: 83%Severity: 52%
Audit Metadata
Analyzed At
May 3, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmboum%2F@762f50e29a84690c0afa34fb35e50d563aaf2a65