apicurio-registry

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is internally coherent as a Membrane-based Apicurio integration, and its installer appears official, so this is not confirmed malware. However, it routes authentication, API actions, and proxy traffic through Membrane rather than directly to Apicurio, creating meaningful intermediary trust and credential-handling risk; combined with unpinned CLI installation, this makes the skill medium risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 29, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapicurio-registry%2F@e47a7e2e789bae7d664332270e7e5decfa549349
Security Audit — socket — apicurio-registry