rydoo

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose matches its capabilities, and the CLI install path is same-org via npm, so this is not overt malware. However, the integration is materially mediated by Membrane rather than directly by Rydoo, so Rydoo credentials, sessions, and business data are routed through a third-party platform with dynamic server-side action creation. That intermediary data flow and unpinned CLI install make the skill medium risk.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
May 1, 2026, 12:08 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Frydoo%2F@df350319167f951c49a43a523de0f5b4d5f2623b
Security Audit — socket — rydoo