qualaroo

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated Qualaroo purpose is plausible, and the CLI install source appears legitimate, but the actual integration routes authentication and API traffic through Membrane as a third-party intermediary rather than directly to Qualaroo. This creates medium-high security risk from credential delegation, proxy access, and mutable CLI installs, though there is no clear evidence of malware or obfuscation.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:29 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fqualaroo%2F@5914b695023b269baa052e2964e54564daffb0bf
Security Audit — socket — qualaroo