ploi

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the install source appears official to Membrane, not an obvious malware lure. However, all Ploi access, auth, and action execution are routed through Membrane instead of Ploi's official direct API, creating a meaningful third-party credential/data trust boundary; combined with mutable `@latest` installs and action auto-generation, this makes the skill medium risk rather than benign.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fploi%2F@08ee9e5013b4981298b8a0d8c95325b38e8f8234
Security Audit — socket — ploi