tolgee

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core function is coherent, and the CLI appears to come from the official Membrane publisher via npm, so this is not confirmed malware. However, the Tolgee integration is mediated through Membrane for authentication, action execution, and raw API proxying, creating a notable third-party trust and data-flow expansion relative to a direct Tolgee integration.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 29, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftolgee%2F@abdafc976e7d487c34b0b7f95764757659efdf39
Security Audit — socket — tolgee