totango

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is plausible and its CLI comes from an official registry, but the real data flow is through Membrane as an intermediary for authentication, token refresh, and API proxying rather than direct Totango endpoints. That expanded trust boundary is proportionate to the vendor's platform model but should be treated as medium risk, not benign direct integration.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 02:46 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftotango%2F@2d328f2b5a6a2c63727295450ffe258654f73956
Security Audit — socket — totango