tripetto

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly coherent with its stated purpose, but it requires trusting Membrane as an intermediary for Tripetto credentials and data, and it installs an unpinned external CLI from npm. This is not overtly malicious, but the third-party credential/data routing and mutable install path make it higher risk than a direct official Tripetto integration.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
May 2, 2026, 01:44 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Ftripetto%2F@7275fbe424b2be24d44645826b89cefb51c10902
Security Audit — socket — tripetto