melo

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is not overt malware, and it uses a plausibly official CLI from npm, but its footprint is inconsistent with its stated Melo purpose and it routes all interaction through Membrane as a third-party intermediary. The strongest concern is purpose mismatch plus indirect remote action generation/execution; overall this is a medium-risk skill rather than confirmed malicious content.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 10:20 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmelo%2F@5eb365e322d1cb438da0d531421e22ecdfe4e361
Security Audit — socket — melo