amilia

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its stated Amilia integration purpose, and the CLI comes from an official npm package tied to Membrane. However, all authentication and data access are routed through Membrane rather than directly to Amilia, creating a disclosed but material intermediary trust and credential-forwarding risk; combined with an unpinned global CLI install, this makes the skill medium risk rather than benign.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
Apr 29, 2026, 04:11 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Familia%2F@8fd0fd00c969e83af82de599e69a462e13e0d2a6
Security Audit — socket — amilia