apptweak

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's general purpose matches AppTweak integration, and the CLI source appears official, so this is not overtly malicious. However, the integration is mediated entirely by Membrane, which stores/manages credentials server-side and proxies requests instead of using AppTweak's official API directly; that third-party credential and data routing makes the footprint broader than a simple direct AppTweak skill.

Confidence: 87%Severity: 54%
Audit Metadata
Analyzed At
Apr 28, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fapptweak%2F@ed9a39a491d923dae81ee6441fa30afd2288e13d
Security Audit — socket — apptweak