1password

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose matches 1Password automation, and the install path is same-vendor and registry-based, so it is not overt malware. However, the actual integration is mediated through Membrane rather than directly using 1Password's official client/API path, meaning sensitive password-manager data and auth are routed through a third-party service with unpinned CLI execution. This is coherent but higher-risk than a direct 1Password integration.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:09 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2F1password%2F@be33f25d126f9446a953f45868af6ffa9b0dc60e
Security Audit — socket — 1password