abstract

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose and capabilities mostly align for an Abstract integration, and the CLI comes from an official npm package rather than an obviously rogue installer. The main concern is data-flow integrity: all authentication and API operations are routed through Membrane as an intermediary instead of directly to Abstract, so users must trust a third-party platform and CLI with account access and data handling. This is not clearly malicious, but it is broader and riskier than a direct API integration.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 2, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fabstract%2F@48986e2b2d7c6d1cbea384a466a95b7cb7962421
Security Audit — socket — abstract