alchemer

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated purpose, and the CLI comes from an official npm package aligned with the publisher. However, all Alchemer access and credentials are routed through Membrane as a third-party intermediary, and the skill installs an unpinned global CLI. This is not clearly malicious, but the brokered data flow and credential handling make it higher risk than a direct official API integration.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Falchemer%2F@750d52c5612a93f7c5f929f72706c2af986a22ff
Security Audit — socket — alchemer