smoove

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is coherent as a Membrane-based Smoove connector, and the CLI source appears official, but it routes authentication and Smoove data through Membrane rather than the official Smoove API directly. The main risks are third-party credential custody and intermediary data flow, plus unpinned `@latest` CLI execution; this is not confirmed malware.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
May 2, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fsmoove%2F@9cdda869c3f81f569b96611bbe0e7f7b06b523e6