amlbot

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is mostly coherent with its stated AMLBot integration purpose, and the CLI comes from an official-looking npm package tied to the same product ecosystem. However, all AMLBot access is mediated through Membrane, which stores credentials server-side and acts as a third-party control plane; combined with mutable `@latest` CLI installs and dynamic action creation, this creates medium security risk even without clear evidence of malicious intent.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
May 3, 2026, 04:33 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Famlbot%2F@10d4a829495e4acecc99134953280f20c9f15113