airops

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent for a Membrane-mediated AirOps integration and uses an official npm package, so it does not look malicious. However, it routes authentication, action execution, and potentially sensitive AirOps data through Membrane instead of direct AirOps APIs, creating meaningful third-party trust and data-flow risk; the unpinned @latest install adds moderate supply-chain exposure.

Confidence: 87%Severity: 52%
Audit Metadata
Analyzed At
Apr 28, 2026, 08:47 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fairops%2F@e7425f3df91439df40af4b26b9aa06f5c2e22f33
Security Audit — socket — airops