tolgee
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's core function is coherent, and the CLI appears to come from the official Membrane publisher via npm, so this is not confirmed malware. However, the Tolgee integration is mediated through Membrane for authentication, action execution, and raw API proxying, creating a notable third-party trust and data-flow expansion relative to a direct Tolgee integration.
Confidence: 85%Severity: 62%
Audit Metadata