melange-qcom
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The workflow is internally consistent with a Qualcomm model-management skill, but it requires an unverifiable `melange-qcom` CLI and routes Melange API credentials through it. Because the binary's official provenance is not established and it handles credentials plus model data, this is high security risk even without proof of malicious intent.
Confidence: 84%Severity: 84%
Audit Metadata