neonomics

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is coherent in purpose and uses an official same-org npm CLI, so it does not look overtly malicious. The main concerns are that all Neonomics operations are proxied through Membrane, `@latest` is unpinned, local CLI credentials may exist despite the docs’ framing, and the skill can enable real-world financial actions through a third-party intermediary.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
May 1, 2026, 12:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fneonomics%2F@dabb824af5dbd0f7077894e06b97e0ce1db8c5f2
Security Audit — socket — neonomics