toucan-toco

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align, and the CLI comes from npm rather than an obviously untrusted installer. However, all Toucan Toco authentication and API traffic are intentionally routed through Membrane's intermediary service/proxy instead of directly to Toucan Toco, which creates notable third-party credential and data-flow risk. This looks more like a legitimate but higher-trust integration layer than confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftoucan-toco%2F@c5647161c6ad68d63a350a6135ccf52684ffe0bd
Security Audit — socket — toucan-toco