yoco

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is broadly aligned with its stated Yoco integration purpose and uses an official Membrane CLI from npm, so it does not look outright malicious. However, it routes Yoco authentication and data through Membrane as an intermediary, uses mutable `@latest` CLI execution, and enables payment-affecting actions plus dynamic action creation, making the trust and data-flow footprint moderately risky for an AI agent skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 30, 2026, 09:16 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fyoco%2F@1b313d660e2f73dec92dd2c7d90968b0f6c10435