trio

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly fits its stated purpose, and the Membrane CLI install path appears official. However, all app access and credentials are brokered through Membrane rather than direct Trio APIs, `@latest` is used for executable installs, and the linked Trio documentation appears mismatched to the claimed product. This looks more like a legitimate but trust-expanding intermediary integration than confirmed malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftrio%2F@7b767d9744695f0d469f98bf9b7a50951e902df0
Security Audit — socket — trio