noyo

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align, and the CLI comes from the expected vendor via npm, so this is not strongly indicative of malware. However, all Noyo access and auth are mediated through Membrane rather than direct official Noyo API flows, and the skill uses unpinned `@latest` CLI execution plus a broad proxy mechanism, creating meaningful third-party trust and data-flow risk.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fnoyo%2F@34766a91d7b8e9d1727582cd57653bc050cbcda9
Security Audit — socket — noyo