rutter
Warn
Audited by Socket on May 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is coherent with its stated Rutter-integration purpose and uses a legitimate npm-distributed CLI, but it routes authentication and API traffic through Membrane as an intermediary rather than direct Rutter endpoints. That disclosed proxy model and mutable CLI install create medium security risk, though not strong evidence of malware.
Confidence: 86%Severity: 56%
Audit Metadata