melo
Warn
Audited by Socket on Sep 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is not overtly malicious and uses an official npm-distributed CLI, but it is internally inconsistent about what Melo is and routes authentication plus API access through Membrane rather than clearly documented official Melo endpoints. The third-party broker model and mismatched purpose details make the footprint only partially aligned with the claimed integration.
Confidence: 87%Severity: 56%
Audit Metadata