melo

Warn

Audited by Socket on Sep 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI, but it is internally inconsistent about what Melo is and routes authentication plus API access through Membrane rather than clearly documented official Melo endpoints. The third-party broker model and mismatched purpose details make the footprint only partially aligned with the claimed integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Sep 19, 2026, 12:14 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmelo%2F@62e61eb92d611e92aedf643b96a5b6153f699556bfd4d77db7c7a917510bae38
Security Audit — socket — melo