ortto

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's functionality is broadly aligned with its stated Ortto integration purpose and the CLI appears to be an official same-org npm package, so this is not confirmed malware. However, all authentication and API traffic are mediated by Membrane rather than going directly to Ortto, creating a third-party credential and data handling dependency, and the skill enables impactful actions like sending messages and deleting or updating records.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 01:17 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fortto%2F@0f2f3c5a34e84be1eee6ee7c8e872228c4499dad
Security Audit — socket — ortto